SUSPICIOUS — 780902e3b73614a.pdf
SUSPICIOUS — 780902e3b73614a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9f08c43e8d35b6eb6cb0af7834c36d0a08cce37ed9f6fef1faee226ea5eff8f5 - SHA-1:
1e785ebd079f86c44e4ceb06e5be7bacf7eaa090 - MD5:
559326c42829a2b64bce0e5f666c3db6 - ssdeep:
1536:kGFDeVEQ8weCm00oXh4VmqT+Joa+A+aITy:xFDeVZSCm0HXh4VZyoa+t+ - TLSH:
T18834AFF310ABED8C77C6AB13DDB62555608AC74D6136C7A049D8B72CC0BC6ACBE50920 - Submitted as: 780902e3b73614a.pdf
- File type: pdf · Size: 52727 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=skyrim%20alchemy%20guide%20ingredient%20effe, https://site-1037196.mozfiles.com/files/1037196/sikoxazobopar.pdf, https://site-1038777.mozfiles.com/files/1038777/17302314347.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=skyrim%20alchemy%20guide%20ingredient%20effe
- https://site-1037196.mozfiles.com/files/1037196/sikoxazobopar.pdf
- https://site-1038777.mozfiles.com/files/1038777/17302314347.pdf
- https://site-1039743.mozfiles.com/files/1039743/70953995748.pdf
- https://site-1040278.mozfiles.com/files/1040278/81179435947.pdf
- https://site-1038849.mozfiles.com/files/1038849/8402257448.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f872f5702608.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f86f94b367b9.pdf
- https://cdn-cms.f-static.net/uploads/4372101/normal_5f88bf0658d86.pdf
- https://cdn-cms.f-static.net/uploads/4372696/normal_5f88978fbc2f9.pdf
- https://uploads.strikinglycdn.com/files/37c6480e-ad00-44eb-b201-2698d17cd7be/10674060297.pdf
- https://uploads.strikinglycdn.com/files/691e2f85-e376-407c-b965-bd9a3874f751/75640245013.pdf
- https://uploads.strikinglycdn.com/files/e00e5c90-b38e-4370-9c2c-18946dddaeb8/pegaditu.pdf
- https://uploads.strikinglycdn.com/files/db965fe1-9e04-40ab-8424-a131a1272ac0/95498369545.pdf
- https://uploads.strikinglycdn.com/files/2a2bfc33-c10f-4447-9193-288693b62463/demagizojefenilof.pdf
- https://site-1043128.mozfiles.com/files/1043128/rikewururekoxetopos.pdf
- https://site-1043120.mozfiles.com/files/1043120/babimomixale.pdf
- https://site-1042919.mozfiles.com/files/1042919/52309208815.pdf
- https://uploads.strikinglycdn.com/files/baa6b2b0-7455-46f0-bea4-445c6ba2acdb/43137518978.pdf
- https://uploads.strikinglycdn.com/files/e5a78887-f4d3-47b5-8a22-4f0b343db3c2/50185451651.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- site-1037196.mozfiles.com
- site-1038777.mozfiles.com
- site-1039743.mozfiles.com
- site-1040278.mozfiles.com
- site-1038849.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1043128.mozfiles.com
- site-1043120.mozfiles.com
- site-1042919.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report