SUSPICIOUS — a2089410.pdf
SUSPICIOUS — a2089410.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
94c35aa6c19cfa2277e8812cf7f5473547bcddf5e0b78a671f5bd0a76601eaf5 - SHA-1:
d7644668a45e3705ec05de5743d91215768cac83 - MD5:
ea58da72ff7c3d27a6dd2f285ae499da - ssdeep:
768:JgGzpDOp1ZsS3Pfn6f7nPxrsJqVpCQAx3NLLiU7a3eAjgEhgZY/3kW5RmWr0B2yy:qGFqpnoiF0cI0W5RmWyUUq - TLSH:
T1EE329EF75053ED4D7A87DB13AEEE296DA545D389213397A400882B2CD87C3BD7E40960 - Submitted as: a2089410.pdf
- File type: pdf · Size: 45135 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=holt%20physical%20science%20interactive%20textbook%20answers%20pdf, https://cdn.shopify.com/s/files/1/0497/6794/0250/files/xotiduvetulafi.pdf, https://cdn.shopify.com/s/files/1/0268/8188/4329/files/kunadebaze.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=holt%20physical%20science%20interactive%20textbook%20answers%20pdf
- https://cdn.shopify.com/s/files/1/0497/6794/0250/files/xotiduvetulafi.pdf
- https://cdn.shopify.com/s/files/1/0268/8188/4329/files/kunadebaze.pdf
- https://cdn.shopify.com/s/files/1/0497/8851/8562/files/94960398438.pdf
- https://cdn.shopify.com/s/files/1/0266/9546/7195/files/titanium_alloy_properties.pdf
- https://cdn.shopify.com/s/files/1/0499/8276/7267/files/60901269131.pdf
- https://cdn.shopify.com/s/files/1/0483/5849/0261/files/34129000903.pdf
- https://cdn.shopify.com/s/files/1/0435/4703/3752/files/bumutasulafimer.pdf
- https://cdn.shopify.com/s/files/1/0430/8510/3258/files/cast_of_scary_movie_five.pdf
- https://cdn.shopify.com/s/files/1/0476/7481/8726/files/1912173392.pdf
- https://cdn-cms.f-static.net/uploads/4370561/normal_5f8d5c5d74b83.pdf
- https://cdn-cms.f-static.net/uploads/4389394/normal_5f8e21dc2fa1a.pdf
- https://cdn.shopify.com/s/files/1/0436/4386/3198/files/91860547710.pdf
- https://cdn.shopify.com/s/files/1/0502/8721/4765/files/gartic_io_1.4.11_apk.pdf
- https://cdn-cms.f-static.net/uploads/4379385/normal_5f8abd8750404.pdf
- https://cdn-cms.f-static.net/uploads/4369651/normal_5f8d5af865ed1.pdf
- https://cdn-cms.f-static.net/uploads/4375515/normal_5f899ae46d4b9.pdf
- https://cdn-cms.f-static.net/uploads/4369161/normal_5f8caa40cb847.pdf
- https://cdn-cms.f-static.net/uploads/4379221/normal_5f8a782453644.pdf
- https://cdn-cms.f-static.net/uploads/4376858/normal_5f8cef0487e11.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report