SUSPICIOUS — 3258008.pdf
SUSPICIOUS — 3258008.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
92e9be5ce72a7260f0d38969983ad6e26cdd071b0651fa1b0f79f7a687dc4a11 - SHA-1:
db5032c2e3578007a6e4dfce8af9991509478ccc - MD5:
d6ad3d31c64ebde117588047c3cacec5 - ssdeep:
768:5gGzpDae1xeMcvqcju9Ps0OeoBM/Pv0f2PZ0WXOsaHAI2U2HAXw9HciX5y8NOsq:6GFue1QMDcScYPq2PZ0qOsaHwwi8iXfO - TLSH:
T123329DF39053DC8C7BCBAB137DB711156186C78931329AA068C87B6CC4BC6BD6E50A60 - Submitted as: 3258008.pdf
- File type: pdf · Size: 45553 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=mariculture%20and%20aquaculture%20pdf, https://uploads.strikinglycdn.com/files/46b8a029-7cf0-4dab-8ce4-08de54956276/nofaxokobubolalijasup.pdf, https://uploads.strikinglycdn.com/files/bb1c0eb5-2ff6-4d86-a3f6-fcec7ea34552/28878006313.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=mariculture%20and%20aquaculture%20pdf
- https://uploads.strikinglycdn.com/files/46b8a029-7cf0-4dab-8ce4-08de54956276/nofaxokobubolalijasup.pdf
- https://uploads.strikinglycdn.com/files/bb1c0eb5-2ff6-4d86-a3f6-fcec7ea34552/28878006313.pdf
- https://uploads.strikinglycdn.com/files/143876a0-a248-4e7f-b4bf-863fb0a47b5d/bekipepigazogexis.pdf
- https://uploads.strikinglycdn.com/files/6c20b18c-51c3-4903-a29a-3dacb9d2f58a/sabiwejuwudawagezar.pdf
- https://cdn-cms.f-static.net/uploads/4371553/normal_5f8870e5000ee.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f92095d7c925.pdf
- https://s3.amazonaws.com/punurum/amharic_writing.pdf
- https://s3.amazonaws.com/kavitokolezub/98507179505.pdf
- https://s3.amazonaws.com/fodose/94285140061.pdf
- https://s3.amazonaws.com/vufupu/elementary_number_theory_textbook.pdf
- https://cdn.shopify.com/s/files/1/0480/9441/2963/files/74841355702.pdf
- https://cdn.shopify.com/s/files/1/0501/6325/3409/files/free_fire_hack_diamantes_apk_obb.pdf
- https://cdn.shopify.com/s/files/1/0480/5787/6644/files/susejuvu.pdf
- https://uploads.strikinglycdn.com/files/b4b50b39-dc64-43b7-9a0b-2506e6a364e3/jipolijefim.pdf
- https://uploads.strikinglycdn.com/files/2fec81d4-7a41-40a7-b3c5-cd36f0c21e47/bezaledutunatarufal.pdf
- https://uploads.strikinglycdn.com/files/677c2131-0253-49d6-8897-73c9c8792e41/ritaweguzaxutu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report