SUSPICIOUS — 272811.pdf
SUSPICIOUS — 272811.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
8477b2b23ae608f8ce4f28104f79e908c00f0420482f1cf129f951be9bff6d73 - SHA-1:
19b24ca77c8e193959b2cf840cc6df3f742abf96 - MD5:
a0e2471b8b5d57bb362a2a0feb5014fb - ssdeep:
1536:MGFcp2waZHifEFkciUn1VKKZkDDhLaHTm:pFcptaZCfCFp1VK1RmC - TLSH:
T1DD35AEF32097EC0D7B8B5B03ADAB116AA149D7089133AB90458C772CD5BCAEE7F10615 - Submitted as: 272811.pdf
- File type: pdf · Size: 59041 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=microscope%20pdf%20rpg, https://cdn-cms.f-static.net/uploads/4368740/normal_5f87b05445ab3.pdf, https://cdn-cms.f-static.net/uploads/4367925/normal_5f87650659ad1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=microscope%20pdf%20rpg
- https://cdn-cms.f-static.net/uploads/4368740/normal_5f87b05445ab3.pdf
- https://cdn-cms.f-static.net/uploads/4367925/normal_5f87650659ad1.pdf
- https://cdn-cms.f-static.net/uploads/4369308/normal_5f87c728b1d3c.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f87f3078104b.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f87044da8efe.pdf
- https://cdn.shopify.com/s/files/1/0433/7162/6659/files/beccaria_and_bentham_argued_that_punishment_should.pdf
- https://cdn.shopify.com/s/files/1/0490/0651/0247/files/poker_night_2_tf2_items.pdf
- https://cdn.shopify.com/s/files/1/0432/1479/9012/files/zabobusunusi.pdf
- https://cdn.shopify.com/s/files/1/0432/2174/5822/files/nekivi.pdf
- https://cdn.shopify.com/s/files/1/0493/7108/7007/files/hawaii_doe_calendar_2021-22.pdf
- https://cdn.shopify.com/s/files/1/0432/6529/4504/files/93464011290.pdf
- https://cdn.shopify.com/s/files/1/0499/2889/6674/files/clash_of_clans_developer_version_apk_hack.pdf
- https://cdn.shopify.com/s/files/1/0438/3699/7792/files/best_gaming_tablet_android_2020.pdf
- https://cdn.shopify.com/s/files/1/0497/9474/4482/files/golden_bird_golden_temple.pdf
- https://cdn-cms.f-static.net/uploads/4366633/normal_5f8744c6d65a7.pdf
- https://cdn-cms.f-static.net/uploads/4368752/normal_5f87c7848a81d.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f87ec6090885.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_5f8756129e056.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f874be646a8f.pdf
- https://cdn-cms.f-static.net/uploads/4366382/normal_5f87db594e8b9.pdf
- https://cdn-cms.f-static.net/uploads/4369496/normal_5f87d7cd711e1.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f872a61225bc.pdf
- https://site-1041784.mozfiles.com/files/1041784/27138314623.pdf
- https://site-1038811.mozfiles.com/files/1038811/25048642229.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1041784.mozfiles.com
- site-1038811.mozfiles.com
- site-1044161.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report