SUSPICIOUS — 7864591.pdf
SUSPICIOUS — 7864591.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
8c116677555955e9e86d2d74a4258b7bed81165f9a08a4d91d0c0b520e0ae7b4 - SHA-1:
4c6282bddd4c7a2debd1ac9cafe185ac8bd3f826 - MD5:
5cc63d4eaed35a43bd704cfd12263c93 - ssdeep:
768:TgGzpDGpR+Hm44cwqQSxP907DpwEmsT4LsIHbTeuwWJD+JoigJZ08oK44:sGFapRHbjIH/eufJD+Joig08h44 - TLSH:
T1CC315CF310A7DD4C7A8BAF436EBB1568A14AD78D612297A484CC676CC4B873D3F10960 - Submitted as: 7864591.pdf
- File type: pdf · Size: 41075 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=under%20armour%20youth%20size%20chart%20pants, https://cdn-cms.f-static.net/uploads/4365636/normal_5f8713613c4d6.pdf, https://cdn-cms.f-static.net/uploads/4367017/normal_5f885d936c564.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=under%20armour%20youth%20size%20chart%20pants
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f8713613c4d6.pdf
- https://cdn-cms.f-static.net/uploads/4367017/normal_5f885d936c564.pdf
- https://cdn-cms.f-static.net/uploads/4367313/normal_5f8752fda3a38.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f870d053f6eb.pdf
- https://uploads.strikinglycdn.com/files/fdf15b18-cec7-426f-91f9-d74fdf091ba0/lixokevagilulidakiviwu.pdf
- https://uploads.strikinglycdn.com/files/c422671f-a6a5-458d-9841-e315b7346846/48625652466.pdf
- https://uploads.strikinglycdn.com/files/6ce547ec-5abf-4ee5-a3b0-364ceb87aeea/vedurukiruxad.pdf
- https://uploads.strikinglycdn.com/files/79932300-7b33-4bdb-a909-ea56d28b4248/vujivuf.pdf
- https://uploads.strikinglycdn.com/files/b741a1b6-430c-4d1a-a228-7920dfcdb925/82786276729.pdf
- https://cdn-cms.f-static.net/uploads/4370087/normal_5f881d1c68523.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f8727af8409c.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f873f6464018.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f87530762c77.pdf
- https://cdn-cms.f-static.net/uploads/4366959/normal_5f87461634f3d.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f8811de217f4.pdf
- https://uploads.strikinglycdn.com/files/0a328a46-e315-450f-b199-fdea115ad328/zajevun.pdf
- https://uploads.strikinglycdn.com/files/a8d489b5-8787-4cdc-8ee5-0d231f43b9f1/43492807053.pdf
- https://uploads.strikinglycdn.com/files/2355488f-1595-4592-94ed-021b87457fbd/53112305296.pdf
- https://uploads.strikinglycdn.com/files/bd7e38a8-5d3d-411b-b071-d5b4cd79e5b7/xobefa.pdf
- https://site-1048178.mozfiles.com/files/1048178/12740548988.pdf
- https://site-1040084.mozfiles.com/files/1040084/descargar_cube_acr_premium_apk.pdf
- https://site-1043098.mozfiles.com/files/1043098/5122161328.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1048178.mozfiles.com
- site-1040084.mozfiles.com
- site-1043098.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report