SUSPICIOUS — 194968a49.pdf
SUSPICIOUS — 194968a49.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
6c409f601a49f936331080c25e7ae2ac6a4b3665a762279e121c63818a951848 - SHA-1:
5fd78505696662407d9193aab5efa35e6b6cce20 - MD5:
721b5f855e2c5af2d3f82fdba0921043 - ssdeep:
768:dgGzpDNpNIeH7g1uxMuYLj/8r/CwP+rSHyxR+v3WzzFsCTIj5oF3DN:eGFRpNl7PQSZv3WnFs3j5oF3DN - TLSH:
T1E432AEF35497EC4CBA868F036CEB261A654AC7496036D3A000DC7A2CD5BC6BDBF10561 - Submitted as: 194968a49.pdf
- File type: pdf · Size: 44102 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=new%20england%20colonies%20vs%20chesapeake%20c, https://cdn.shopify.com/s/files/1/0433/4741/1096/files/how_to_program_rca_universal_remote_rcr3273r.pdf, https://cdn.shopify.com/s/files/1/0428/0736/1703/files/makusodupakazawez.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=new%20england%20colonies%20vs%20chesapeake%20c
- https://cdn.shopify.com/s/files/1/0433/4741/1096/files/how_to_program_rca_universal_remote_rcr3273r.pdf
- https://cdn.shopify.com/s/files/1/0484/1983/1960/files/tuzejogazajuzewuke.pdf
- https://cdn.shopify.com/s/files/1/0428/0736/1703/files/makusodupakazawez.pdf
- https://site-1038629.mozfiles.com/files/1038629/12837394018.pdf
- https://site-1039848.mozfiles.com/files/1039848/xakabo.pdf
- https://site-1041284.mozfiles.com/files/1041284/kulekanekenateg.pdf
- https://site-1043239.mozfiles.com/files/1043239/gezusejogeboripepitewel.pdf
- https://site-1048568.mozfiles.com/files/1048568/tavuwilaw.pdf
- https://site-1038837.mozfiles.com/files/1038837/rajufuvozut.pdf
- https://site-1038969.mozfiles.com/files/1038969/80413625524.pdf
- https://site-1038887.mozfiles.com/files/1038887/lodivojetizix.pdf
- https://cdn.shopify.com/s/files/1/0496/8277/6221/files/tv_guide_neenah_wi.pdf
- https://cdn.shopify.com/s/files/1/0483/5701/5701/files/stickers_argentina_whatsapp_apk.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/9639254.pdf
- https://gurigibafex.weebly.com/uploads/1/3/0/7/130739571/88b40badd.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f871bfb285f7.pdf
- https://cdn-cms.f-static.net/uploads/4367952/normal_5f879b10a5159.pdf
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f877d5a1af6e.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f877c30a0689.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f87b1d13c8d7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1038629.mozfiles.com
- site-1039848.mozfiles.com
- site-1041284.mozfiles.com
- site-1043239.mozfiles.com
- site-1048568.mozfiles.com
- site-1038837.mozfiles.com
- site-1038969.mozfiles.com
- site-1038887.mozfiles.com
- tavumake.weebly.com
- gurigibafex.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report