SUSPICIOUS — 5808179.pdf
SUSPICIOUS — 5808179.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9ee96da8cb5526ec5557f605c31e79ed2fb2f0aceb2a9307062fb1b0972b8135 - SHA-1:
66b43c63ba7e275e7ded5323a130297aba8f7118 - MD5:
94ef02e462d1242dc5fdeefcecfc4d29 - ssdeep:
768:GgGzpDspFwoUhzrFMeNNe9Egh2u3V7dQMlt615bIZMO3VgF14i9bErOLohD:TGFwpv3ViMlcLCMOSF7gO0hD - TLSH:
T12A328DF750A7ED4C7E879B07ADA611A9604DD788A027D7A048CC6B2CC4BC6ED7F10960 - Submitted as: 5808179.pdf
- File type: pdf · Size: 44658 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=the%20heist%202%20game, https://cdn-cms.f-static.net/uploads/4365542/normal_5f87100f2f38a.pdf, https://cdn-cms.f-static.net/uploads/4366003/normal_5f87209c2fdce.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=the%20heist%202%20game
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f87100f2f38a.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f87209c2fdce.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f872035802ec.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f87348064a28.pdf
- https://cdn-cms.f-static.net/uploads/4366397/normal_5f87cc458dc55.pdf
- https://cdn-cms.f-static.net/uploads/4367310/normal_5f87b3afdd8d6.pdf
- https://cdn-cms.f-static.net/uploads/4366956/normal_5f87776227875.pdf
- https://cdn.shopify.com/s/files/1/0493/5856/9628/files/auttaja_bot_discord.pdf
- https://cdn.shopify.com/s/files/1/0480/9641/1812/files/medela_harmony_breast_pump_parts.pdf
- https://cdn.shopify.com/s/files/1/0499/4387/1643/files/39797456124.pdf
- https://cdn.shopify.com/s/files/1/0436/3000/2336/files/baby_trend_expedition_elx_jogging_stroller.pdf
- https://cdn.shopify.com/s/files/1/0438/4597/6221/files/xumalirimovo.pdf
- https://uploads.strikinglycdn.com/files/b449b336-faa6-47af-927c-9a76348a81fb/34692795198.pdf
- https://uploads.strikinglycdn.com/files/d2930ee8-792d-4c59-9b49-10dba43809a7/10635733569.pdf
- https://uploads.strikinglycdn.com/files/f11efd97-c68a-48ba-abe8-3cd312e6809c/70216406527.pdf
- https://uploads.strikinglycdn.com/files/f57aa49e-a44e-4658-ae65-b3da7ebbf1a7/50458753599.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f8725f350b2a.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f8721ab83f40.pdf
- https://cdn-cms.f-static.net/uploads/4370078/normal_5f8849d55d90e.pdf
- https://site-1042835.mozfiles.com/files/1042835/48607007238.pdf
- https://site-1038482.mozfiles.com/files/1038482/gekogodimexurab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1042835.mozfiles.com
- site-1038482.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report