SUSPICIOUS — 4368256.pdf
SUSPICIOUS — 4368256.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9057d7ba7a6d3b736ef608f411f17c8f6e185cf85f4056f33eba72a3428d1afb - SHA-1:
92b85d9500c229695ff42a276c1ccc046514d67f - MD5:
e05b67d0a49c5e23932b2f86eae04395 - ssdeep:
1536:jGFppLG/Uv7dxG857rWJcrXK8W+iE+WJ7aKtoaT:yFppa/Kd553WqrXK8WY/ac - TLSH:
T14A349DF3049BED4CBA899B43A8BB1055658AC3CC7276A790588C7B2DD07C6BDBE10950 - Submitted as: 4368256.pdf
- File type: pdf · Size: 56723 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=chello%20divas%202%20release%20date, https://uploads.strikinglycdn.com/files/ed7b530e-d6ba-4a25-b45c-20601fae03c6/kolofawugoli.pdf, https://uploads.strikinglycdn.com/files/8d80b7a2-15f7-4c65-816a-1c7852bd8f3b/97740597152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=chello%20divas%202%20release%20date
- https://uploads.strikinglycdn.com/files/ed7b530e-d6ba-4a25-b45c-20601fae03c6/kolofawugoli.pdf
- https://uploads.strikinglycdn.com/files/8d80b7a2-15f7-4c65-816a-1c7852bd8f3b/97740597152.pdf
- https://uploads.strikinglycdn.com/files/433fec2f-81a5-4392-8397-e7e07233dc7f/dixobipugolanitikop.pdf
- https://uploads.strikinglycdn.com/files/5b7431a2-3438-4827-a7af-8689c088e875/51280600153.pdf
- https://uploads.strikinglycdn.com/files/37333956-b400-4222-8a9d-08cea38a5830/77214361049.pdf
- https://cdn.shopify.com/s/files/1/0476/5794/3206/files/berefep.pdf
- https://cdn.shopify.com/s/files/1/0483/9800/8472/files/12732494047.pdf
- https://cdn.shopify.com/s/files/1/0486/4632/4382/files/trotec_speedy_300_manual.pdf
- https://cdn.shopify.com/s/files/1/0482/1070/6619/files/laxifuder.pdf
- https://cdn.shopify.com/s/files/1/0505/5437/2261/files/6920981185.pdf
- https://site-1042917.mozfiles.com/files/1042917/kizenixi.pdf
- https://site-1042347.mozfiles.com/files/1042347/40357649373.pdf
- https://site-1040600.mozfiles.com/files/1040600/83772004336.pdf
- https://site-1042444.mozfiles.com/files/1042444/21452604317.pdf
- https://site-1048575.mozfiles.com/files/1048575/66501303887.pdf
- https://site-1038971.mozfiles.com/files/1038971/vafimo.pdf
- https://site-1036924.mozfiles.com/files/1036924/75109326725.pdf
- https://site-1040210.mozfiles.com/files/1040210/19542151270.pdf
- https://cdn.shopify.com/s/files/1/0434/7189/6741/files/nozarugavafasotodalokusuw.pdf
- https://cdn.shopify.com/s/files/1/0496/3159/2597/files/halliday_resnick_physics.pdf
- https://cdn.shopify.com/s/files/1/0434/6164/0342/files/severna_park_taphouse_trivia.pdf
- https://cdn.shopify.com/s/files/1/0496/7297/8595/files/culligan_medallist_series_manual.pdf
- https://cdn.shopify.com/s/files/1/0480/4313/1044/files/vis_a_vis_season_4_episode_5_cast.pdf
- https://uploads.strikinglycdn.com/files/fa340da5-12be-4f50-a79b-e4f8a72fb375/58946467662.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1042917.mozfiles.com
- site-1042347.mozfiles.com
- site-1040600.mozfiles.com
- site-1042444.mozfiles.com
- site-1048575.mozfiles.com
- site-1038971.mozfiles.com
- site-1036924.mozfiles.com
- site-1040210.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report