SUSPICIOUS — 47903958784.pdf
SUSPICIOUS — 47903958784.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
85b6e27a2fc11bed8270909d12cf313c36f4683e68f2a35ec99942e1372beb94 - SHA-1:
053674bda6f19ee6a2556199360a6ae9898e63a8 - MD5:
0a5a80170b6e86b171ce93a9b4511290 - ssdeep:
768:ObgGzpDaO/8JlOcd5EO87Dx9vNhKsdW2ctTteBqAB6iG77WoyKHr5AHx:tGFuO/8oO+L+tTQBLNGvWoyKHr5AR - TLSH:
T1F8317DF350A7DD8C7ACBA70358EB1469204AC68C6176D7A45989376CC0FC2BDBF60960 - Submitted as: 47903958784.pdf
- File type: pdf · Size: 41118 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=fiction+vs+nonfiction+sort+pdf, https://uploads.strikinglycdn.com/files/bcffbf3a-7b01-4bac-bf6d-8e45cc4ac947/lefamudipo.pdf, https://uploads.strikinglycdn.com/files/09855d7a-3cd5-4c25-afa3-0c1d8e33b56f/vegulobimo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=fiction+vs+nonfiction+sort+pdf
- https://uploads.strikinglycdn.com/files/bcffbf3a-7b01-4bac-bf6d-8e45cc4ac947/lefamudipo.pdf
- https://uploads.strikinglycdn.com/files/09855d7a-3cd5-4c25-afa3-0c1d8e33b56f/vegulobimo.pdf
- https://uploads.strikinglycdn.com/files/4a198172-f7ce-44e4-ba4a-d644dec04586/21828439250.pdf
- https://cdn.shopify.com/s/files/1/0433/3862/9275/files/40803348525.pdf
- https://cdn.shopify.com/s/files/1/0482/9075/8817/files/20050996549.pdf
- https://cdn.shopify.com/s/files/1/0435/2504/6423/files/10746364942.pdf
- https://cdn.shopify.com/s/files/1/0482/2895/8365/files/tesla_motor_club_model_y.pdf
- https://uploads.strikinglycdn.com/files/50e0a144-9ca0-41c5-bf7c-fa105d77f27f/50459957308.pdf
- https://uploads.strikinglycdn.com/files/a942c532-753d-4036-8f68-25473e63a453/4355471828.pdf
- https://uploads.strikinglycdn.com/files/77bc3d73-06b1-45f6-a92e-b964db0e0228/vugalubunewowizi.pdf
- https://uploads.strikinglycdn.com/files/a8dce123-57f2-4cc5-b8ad-f8d7b3a0dc8b/jugepuwajonanopefisowo.pdf
- https://uploads.strikinglycdn.com/files/4a465180-9a7c-4d84-8819-0a71dd342411/22375076585.pdf
- https://uploads.strikinglycdn.com/files/a9988cc6-363b-4992-8048-c7d7c78930b3/22476927301.pdf
- https://uploads.strikinglycdn.com/files/ade3fa3a-f271-4e3d-a10b-e6cf2f7ccaf8/8639432929.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report