SUSPICIOUS — 9074186.pdf
SUSPICIOUS — 9074186.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
6be58dfc3920823f5e96b5fec93f6cc110c7379db81aae54fc9874bdf391b40e - SHA-1:
efd76220d0b25788373a5799c81c207cd6a67259 - MD5:
b652c375c05566e56d01677846477302 - ssdeep:
768:4gGzpD8pHwAEyuUW1EL/1j+f/hxzoRJVO0OYfNKGc7OHsPud9fuUYvcmaXGqpW2V:VGFIpHY/b4JVOUKx2XWPUz9pW2Wvq - TLSH:
T19D32AFF710A7ED8C3B8FAF436D971469A149D74C6037666049C8372CD0B8AEDAE10A71 - Submitted as: 9074186.pdf
- File type: pdf · Size: 47452 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=victoria:%20an%20empire%20under%20the%20sun, https://cdn-cms.f-static.net/uploads/4372104/normal_5f8a2b0a5f661.pdf, https://cdn-cms.f-static.net/uploads/4379842/normal_5f8bcdbf2c4e5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=victoria:%20an%20empire%20under%20the%20sun
- https://cdn-cms.f-static.net/uploads/4372104/normal_5f8a2b0a5f661.pdf
- https://cdn-cms.f-static.net/uploads/4379842/normal_5f8bcdbf2c4e5.pdf
- https://cdn-cms.f-static.net/uploads/4379968/normal_5f8e8bd99f2b8.pdf
- https://cdn-cms.f-static.net/uploads/4384046/normal_5f8bf05e78445.pdf
- https://pepisukuwen.weebly.com/uploads/1/3/1/6/131606293/natupojikumeb-xovovetogowup-susifinit.pdf
- https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/1486329.pdf
- https://cdn.shopify.com/s/files/1/0266/8799/6085/files/bill_of_rights_printables.pdf
- https://cdn.shopify.com/s/files/1/0501/9982/2520/files/reactor_sector_energetico_mod_apk.pdf
- https://cdn-cms.f-static.net/uploads/4387218/normal_5f8e0ebb3baa5.pdf
- https://cdn-cms.f-static.net/uploads/4370317/normal_5f8f6f7611745.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f8714953d5c2.pdf
- https://cdn-cms.f-static.net/uploads/4368762/normal_5f8e0045e3b8c.pdf
- https://s3.amazonaws.com/henghuili-files/75410197303.pdf
- https://s3.amazonaws.com/henghuili-files2/symbolic_logic_download.pdf
- https://s3.amazonaws.com/jamokaroxoj/astable_multivibrator_using_bjt.pdf
- https://s3.amazonaws.com/sugaguxagu/46307812138.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- pepisukuwen.weebly.com
- jarapitoxedomel.weebly.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report