SUSPICIOUS — 5002527.pdf
SUSPICIOUS — 5002527.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
75aec9744d5ce71584814b2dae6e14b301321deb0be1cb063ffb066cf995917d - SHA-1:
4b02d298dd8ffef81fb18525bdadd17413ca1d2b - MD5:
2536e4305eb284b30794041bc46b0d37 - ssdeep:
1536:OGFppAdId4Io3heOZ1KeLXLztkI5cBvwCTbtDV2:3Fpp6ao3rZkI5crs - TLSH:
T1F9349EF39167DDCC7A8A6B03ADEA11996286C3487032A7A00589777CC5BC6FD7D10A21 - Submitted as: 5002527.pdf
- File type: pdf · Size: 56075 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ugee%20pen%20not%20working, https://cdn.shopify.com/s/files/1/0483/8693/2894/files/90088798925.pdf, https://cdn.shopify.com/s/files/1/0483/3948/4823/files/reporting_verbs_b2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ugee%20pen%20not%20working
- https://cdn.shopify.com/s/files/1/0483/8693/2894/files/90088798925.pdf
- https://cdn.shopify.com/s/files/1/0483/3948/4823/files/reporting_verbs_b2.pdf
- https://cdn.shopify.com/s/files/1/0491/7965/6344/files/63007370758.pdf
- https://cdn.shopify.com/s/files/1/0498/0342/7993/files/69993743448.pdf
- https://cdn.shopify.com/s/files/1/0433/1939/4462/files/xigarobugodisukiwatusazan.pdf
- https://cdn.shopify.com/s/files/1/0427/9966/1223/files/como_alabar_a_dios_en_oracion.pdf
- https://cdn.shopify.com/s/files/1/0435/4539/5368/files/mibogijijuwigawirodugif.pdf
- https://cdn.shopify.com/s/files/1/0481/5509/9287/files/roach_motel_urban_dictionary.pdf
- https://cdn.shopify.com/s/files/1/0484/4719/3238/files/74291103125.pdf
- https://site-1042450.mozfiles.com/files/1042450/kuxawa.pdf
- https://site-1041866.mozfiles.com/files/1041866/jaxeg.pdf
- https://site-1041939.mozfiles.com/files/1041939/86260198523.pdf
- https://site-1039669.mozfiles.com/files/1039669/wibujanubuzuveribarodel.pdf
- https://uploads.strikinglycdn.com/files/c9ca3b17-220d-409d-834a-c1d056ef88c9/76379608187.pdf
- https://uploads.strikinglycdn.com/files/43d4c2a7-1cbb-4e04-8808-feb10f8d2c6b/54512870896.pdf
- https://uploads.strikinglycdn.com/files/662cd1ba-c57c-4ba2-89ba-0a7f8cfdc01d/7346448457.pdf
- https://uploads.strikinglycdn.com/files/f183030a-6ff5-4aa6-a5e0-502374eb8f76/79813405983.pdf
- https://uploads.strikinglycdn.com/files/3e55fcf0-3358-4185-92fa-981930ba35e1/18964230798.pdf
- https://cdn.shopify.com/s/files/1/0496/2910/2244/files/key_to_shark_identification_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0483/6245/5191/files/90547116866.pdf
- https://cdn.shopify.com/s/files/1/0500/9624/2856/files/jon_bon_jovi_dorothea_hurley_karate.pdf
- https://cdn.shopify.com/s/files/1/0434/2625/0917/files/36789726456.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1042450.mozfiles.com
- site-1041866.mozfiles.com
- site-1041939.mozfiles.com
- site-1039669.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report