SUSPICIOUS — 2bba1d0.pdf
SUSPICIOUS — 2bba1d0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
a0cb26eb9c9d92258b7031e4d6356f2b74d5515fab3ca8691fcb9fe7a1136e86 - SHA-1:
90038458a38623e508f390907ca1b21e880f1e09 - MD5:
3f5aae5112e777d8fac8f19bc9a01e6c - ssdeep:
768:BgGzpDrppAuyRFPeJJCSSP3VMAFWRQtpYXjXn+AL+wYVdT3x5yJVm4K3bBtgVP3z:yGF3pTn+nwYrDxYjzWrOPj - TLSH:
T18D316CF35067EC4D3ACA9B03B9EB255D6089DB896132E764808C762DD47C7BD3E40A60 - Submitted as: 2bba1d0.pdf
- File type: pdf · Size: 42407 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hold%20up%20wait%20a%20minute%20lyrics, https://cdn-cms.f-static.net/uploads/4366360/normal_5f872294e49e1.pdf, https://cdn-cms.f-static.net/uploads/4366044/normal_5f87055800fc6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hold%20up%20wait%20a%20minute%20lyrics
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f872294e49e1.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f87055800fc6.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f871197f2ad0.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f87008892136.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f8721e772c67.pdf
- https://cdn.shopify.com/s/files/1/0434/4689/4758/files/nojizimonomikaredes.pdf
- https://cdn.shopify.com/s/files/1/0428/4389/8019/files/29824183497.pdf
- https://cdn.shopify.com/s/files/1/0433/3119/0952/files/conjure_woodland_beings_list_5e.pdf
- https://cdn.shopify.com/s/files/1/0484/0488/9760/files/bilegizume.pdf
- https://cdn.shopify.com/s/files/1/0479/3591/4140/files/25262387124.pdf
- https://site-1043848.mozfiles.com/files/1043848/44018920347.pdf
- https://site-1043396.mozfiles.com/files/1043396/1555632318.pdf
- https://site-1038985.mozfiles.com/files/1038985/30000936658.pdf
- https://site-1040218.mozfiles.com/files/1040218/86494111988.pdf
- https://uploads.strikinglycdn.com/files/33ef12db-3edf-4601-a56b-64aca0dbef42/89458772738.pdf
- https://uploads.strikinglycdn.com/files/cead6078-7a25-4b5f-ace0-160003b66bbf/welaxokugogufagolabo.pdf
- https://uploads.strikinglycdn.com/files/9748429c-a64f-4bb1-b6d9-eef523e52c96/kidujiduvadulojolub.pdf
- https://uploads.strikinglycdn.com/files/d1d13378-4ccb-4a33-bdcd-2868150f18ad/89568303639.pdf
- https://cdn.shopify.com/s/files/1/0496/2392/4885/files/ropa_para_bebs_recin_nacidas.pdf
- https://cdn.shopify.com/s/files/1/0482/8092/8420/files/que_es_un_bosquejo_en_espaol.pdf
- https://cdn.shopify.com/s/files/1/0433/0084/7780/files/44227715324.pdf
- https://cdn.shopify.com/s/files/1/0266/8583/3416/files/zone_de_telechargement_nouvelle_adresse.pdf
- https://cdn.shopify.com/s/files/1/0476/7937/3478/files/original_band_that_sang_i_shot_the_sheriff_crossword.pdf
- https://cdn.shopify.com/s/files/1/0268/8876/5615/files/93695336710.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1043848.mozfiles.com
- site-1043396.mozfiles.com
- site-1038985.mozfiles.com
- site-1040218.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report