SUSPICIOUS — 63891891440.pdf
SUSPICIOUS — 63891891440.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7d9b8db1cd90b101e9fbf1bc8f20543ab00a180768a8b5588650fd44a8f39363 - SHA-1:
3dd50877016f8051283eac36bdceb520aa82b66c - MD5:
69e751bb92cfe3c1470ec1a246834dcc - ssdeep:
1536:4GF1endDaJKV4Ac/Dbs9wij4ZcrQRpQHp:VF1exzebsqiEZeQXA - TLSH:
T17F339EF71097DD8C7B87EF0379FA2128514A974822229B6055D8772DC4BC3BCAE11A61 - Submitted as: 63891891440.pdf
- File type: pdf · Size: 50072 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=ultimate+guitar+tools+apk+cracked, https://uploads.strikinglycdn.com/files/8d9d804e-7e04-4a6a-964f-9529e9f1b1d7/zukelinig.pdf, https://uploads.strikinglycdn.com/files/40fca582-9ccc-407c-9844-46a607370ff6/jifopapowidisup.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=ultimate+guitar+tools+apk+cracked
- https://uploads.strikinglycdn.com/files/8d9d804e-7e04-4a6a-964f-9529e9f1b1d7/zukelinig.pdf
- https://uploads.strikinglycdn.com/files/40fca582-9ccc-407c-9844-46a607370ff6/jifopapowidisup.pdf
- https://uploads.strikinglycdn.com/files/0db79617-6e2c-42aa-b02c-95b2b25900d1/94954800692.pdf
- https://uploads.strikinglycdn.com/files/2dd47f4e-080e-44ac-9ef6-452d3f14aa7f/bilipowililisi.pdf
- https://site-1036852.mozfiles.com/files/1036852/52780216226.pdf
- https://site-1040610.mozfiles.com/files/1040610/xoxumiruxewuzekus.pdf
- https://site-1039921.mozfiles.com/files/1039921/dusak.pdf
- https://uploads.strikinglycdn.com/files/228a5b2b-9546-4f7e-b0f0-d26df2ffc48d/fajazogolufovire.pdf
- https://uploads.strikinglycdn.com/files/12b32e26-4ca5-49c4-a6d4-fa3e4127ee20/sirorililuvupokija.pdf
- https://uploads.strikinglycdn.com/files/3b0f8bf1-f402-48a6-8b27-a4e8a452767c/wogexinatowogukaxuta.pdf
- https://uploads.strikinglycdn.com/files/9f5198a4-cb80-4eaf-a50a-e2c11b7ff559/16094880343.pdf
- https://uploads.strikinglycdn.com/files/e5a4d3d6-8979-4342-85f3-1ac07f52f976/kuzuwudimijud.pdf
- https://uploads.strikinglycdn.com/files/f39af1b6-d296-4417-a67b-aeaf084d4bd5/bobakavitijakebanupag.pdf
- https://uploads.strikinglycdn.com/files/34c7b1c1-1ca1-4b36-a345-c96aecbda912/96298304973.pdf
- https://uploads.strikinglycdn.com/files/850bcd49-eb76-4160-b7f7-19c204fcbe36/kejadu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1036852.mozfiles.com
- site-1040610.mozfiles.com
- site-1039921.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report