SUSPICIOUS — mexaratufadip.pdf
SUSPICIOUS — mexaratufadip.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
98e06df6d11d0f3d82403da66b9677e1b7c3d874c844be4217b12fa063e54340 - SHA-1:
66a9461db4548a54701dc8689ac4d55c4868b72a - MD5:
3e492530ffb0a12dc8d4304ac28406a3 - ssdeep:
1536:OGFbehbi+n+KSwpgUgFD3pKmWCnX+biQYe:3Fb7+n+7wpgUg9pKwX+GC - TLSH:
T1A9358EF350A7EC8C7A8B9F43ADD6205D644ACB4D6132DB9045486B6CD4BC9FC7E10A11 - Submitted as: mexaratufadip.pdf
- File type: pdf · Size: 58440 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=is%20456%20code%20book%20pdf%20free%20download, https://cdn-cms.f-static.net/uploads/4367005/normal_5f874ea394ee9.pdf, https://cdn-cms.f-static.net/uploads/4381528/normal_5f8b69e251444.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=is%20456%20code%20book%20pdf%20free%20download
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f874ea394ee9.pdf
- https://cdn-cms.f-static.net/uploads/4381528/normal_5f8b69e251444.pdf
- https://cdn-cms.f-static.net/uploads/4387825/normal_5f9049d4b418d.pdf
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f915601c00c7.pdf
- https://cdn.shopify.com/s/files/1/0434/0688/5027/files/80546103292.pdf
- https://cdn.shopify.com/s/files/1/0266/8783/2256/files/firewall_zero_hour_trophy_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/9666/4989/files/cheats_para_megaman_zero_4_gba_android.pdf
- https://cdn.shopify.com/s/files/1/0466/3587/6517/files/the_ex_factor_guide_review.pdf
- https://cdn.shopify.com/s/files/1/0479/7172/9564/files/gexejuv.pdf
- https://cdn.shopify.com/s/files/1/0430/3332/9815/files/jafufowegupi.pdf
- https://cdn.shopify.com/s/files/1/0429/9980/8149/files/noxidujozuxi.pdf
- https://cdn.shopify.com/s/files/1/0482/0720/0408/files/unilever_sustainability_report_2020.pdf
- https://cdn.shopify.com/s/files/1/0482/4606/3258/files/osrs_spiritual_mages.pdf
- https://cdn.shopify.com/s/files/1/0486/1748/8549/files/blue_indian_ringneck_parrot.pdf
- https://cdn.shopify.com/s/files/1/0495/5255/6184/files/download_font_for_android_phone_free.pdf
- https://cdn.shopify.com/s/files/1/0476/7481/8726/files/download_manager_and_private_browser_apk.pdf
- https://s3.amazonaws.com/susonanezaj/history_of_english_literature_books_free_download.pdf
- https://s3.amazonaws.com/votuweroxigezog/test_anxiety_definition.pdf
- https://s3.amazonaws.com/zuxime/2878074941.pdf
- https://s3.amazonaws.com/sugaguxagu/43049277575.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f93e6793fb55.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f87506f73747.pdf
- https://cdn-cms.f-static.net/uploads/4369514/normal_5f939f893f755.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f872122119ba.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report