SUSPICIOUS — 80526081181.pdf
SUSPICIOUS — 80526081181.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9dd1bbe07f12b6fb1aab4542b337713f10f4d4408919b27e18eae7233710571c - SHA-1:
a6749ac1ad6be60c6747a3b2ffa639888538bcc0 - MD5:
9dafe6a3f9a04cba04db7be7ed2c666c - ssdeep:
1536:nGFFp6BnTuWyZmZp2hbPILqa+yO5Ift7:GFFp0Hy0WVALHu07 - TLSH:
T15433BFF3009BDC4CB6869B03ACA61065678AD7897233A6A004DC7B7DD4BC6BCBE50570 - Submitted as: 80526081181.pdf
- File type: pdf · Size: 49882 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=camscanner+full+version+cracked+apk, https://uploads.strikinglycdn.com/files/46d4f396-ffc3-4c62-a8d2-0f85403ed318/tefojenanotusaluto.pdf, https://uploads.strikinglycdn.com/files/eff5b6a7-c786-42cd-a18c-db7f54c41634/benatasibovotikabar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=camscanner+full+version+cracked+apk
- https://uploads.strikinglycdn.com/files/46d4f396-ffc3-4c62-a8d2-0f85403ed318/tefojenanotusaluto.pdf
- https://uploads.strikinglycdn.com/files/eff5b6a7-c786-42cd-a18c-db7f54c41634/benatasibovotikabar.pdf
- https://uploads.strikinglycdn.com/files/6236d32c-3332-420d-9ace-8fb5f9716cb8/zefobojemivuzate.pdf
- https://uploads.strikinglycdn.com/files/6732ce7b-e85e-4ba2-8c69-394676514996/71943995469.pdf
- https://cdn.shopify.com/s/files/1/0436/0346/0259/files/wezixofitigovatopez.pdf
- https://cdn.shopify.com/s/files/1/0431/6705/6028/files/34633450048.pdf
- https://cdn.shopify.com/s/files/1/0492/3185/5772/files/frases_de_animo_para_una_amiga_triste.pdf
- https://cdn.shopify.com/s/files/1/0496/7700/9060/files/graduated_cylinder_worksheet_for_middle_school.pdf
- https://cdn.shopify.com/s/files/1/0480/4437/6223/files/adobe_captivate_interactive_video_tutorial.pdf
- https://site-1040767.mozfiles.com/files/1040767/letud.pdf
- https://site-1041084.mozfiles.com/files/1041084/loziwipizilut.pdf
- https://site-1043491.mozfiles.com/files/1043491/vogunawilokekisozabi.pdf
- https://site-1037266.mozfiles.com/files/1037266/zavomamuma.pdf
- https://cdn.shopify.com/s/files/1/0431/4906/6394/files/hangul_alphabet_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0428/3973/6487/files/how_many_square_feet_is_an_average_bedroom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1040767.mozfiles.com
- site-1041084.mozfiles.com
- site-1043491.mozfiles.com
- site-1037266.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report