SUSPICIOUS — 9395878.pdf
SUSPICIOUS — 9395878.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7fbdc141aa38a584b53a1683aac34ffa9e3071aae31128ac0e5ed1a8de4a84fb - SHA-1:
aa865a766622ac0d2f36ede63e99944571d9d859 - MD5:
e93dd823c4b554b098aef7f6bb12e55f - ssdeep:
1536:mGFTp5qSaoP4slPVDwvi1mEhHIsiGWI+aPxDmZ:/FTpLN4slBFH9ihLap8 - TLSH:
T15035AEF750A3EC4CB9CA9F436EBA125A518EC38D6032E795809C262DD17C6ED7E10970 - Submitted as: 9395878.pdf
- File type: pdf · Size: 61099 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=games%20that%20support%20physx, https://cdn-cms.f-static.net/uploads/4366335/normal_5f874a6a8d743.pdf, https://cdn-cms.f-static.net/uploads/4366316/normal_5f870e28c295a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=games%20that%20support%20physx
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f874a6a8d743.pdf
- https://cdn-cms.f-static.net/uploads/4366316/normal_5f870e28c295a.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f86f84a2724d.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f87090738e37.pdf
- https://uploads.strikinglycdn.com/files/c757cf14-4f72-4109-8925-348c9cc6a8a2/91898919401.pdf
- https://uploads.strikinglycdn.com/files/bd07c469-a929-4e0a-8805-34466f8b8d18/98435890438.pdf
- https://uploads.strikinglycdn.com/files/5bff55d9-b682-4896-a2d0-31ead03a4acd/84707608076.pdf
- https://uploads.strikinglycdn.com/files/29ce7841-62a7-43da-b11f-9f0ac72998d2/69500906203.pdf
- https://uploads.strikinglycdn.com/files/2945f45c-aae0-4a1b-aeec-d926913ef53f/dekop.pdf
- https://site-1037149.mozfiles.com/files/1037149/sopuwogafapu.pdf
- https://site-1043447.mozfiles.com/files/1043447/lelaberogadenafi.pdf
- https://site-1038556.mozfiles.com/files/1038556/16181560298.pdf
- https://site-1036981.mozfiles.com/files/1036981/bepajalugobef.pdf
- https://site-1040312.mozfiles.com/files/1040312/41794071616.pdf
- https://uploads.strikinglycdn.com/files/362d91b7-7155-4956-83ba-e608c7762892/21451347015.pdf
- https://uploads.strikinglycdn.com/files/7b9eb9b6-3d6d-4d7c-85a1-dc2cee6d8d63/55523179274.pdf
- https://uploads.strikinglycdn.com/files/f3ba1ac4-e9ee-4ee4-98d0-430e9bef02f2/dujenuwapo.pdf
- https://uploads.strikinglycdn.com/files/2ff1a27c-5ddf-41d0-b1bc-e0d9e6c46eca/59107832900.pdf
- https://site-1043292.mozfiles.com/files/1043292/valitosejopubavilegibisu.pdf
- https://site-1039129.mozfiles.com/files/1039129/rewofasexutedibopobivos.pdf
- https://site-1040521.mozfiles.com/files/1040521/lomovowezexuvarixoluzoku.pdf
- https://site-1042432.mozfiles.com/files/1042432/wonisajemagufigepidiwidan.pdf
- https://site-1041679.mozfiles.com/files/1041679/jobowomugivop.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/wirexanusir.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1037149.mozfiles.com
- site-1043447.mozfiles.com
- site-1038556.mozfiles.com
- site-1036981.mozfiles.com
- site-1040312.mozfiles.com
- site-1043292.mozfiles.com
- site-1039129.mozfiles.com
- site-1040521.mozfiles.com
- site-1042432.mozfiles.com
- site-1041679.mozfiles.com
- fijojonibiw.weebly.com
- jakedekokobara.weebly.com
- rezizeme.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report