SUSPICIOUS — 2358856.pdf
SUSPICIOUS — 2358856.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ac9e22cc73c450fd89251dc9cb9068effeb6205e0ba2f8514698e9192b95503c - SHA-1:
8cda77c83d43a7f75e901e136d9ccd82c28921a7 - MD5:
66a103dea27100a7fe2b497a6bcc493d - ssdeep:
1536:6GFwpoNrSuWDW8HqDFRj8hlPFsRuOgvdrdtKk0RsH6HEZ++viGh:jFwpvUTDFV8hoRyTt70RsH+xa7 - TLSH:
T10D39DFF314D7DC4C7ACBBB43A57A00AA7685D6896276D3A44588732CD07C2EE3F40A51 - Submitted as: 2358856.pdf
- File type: pdf · Size: 91246 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=karakai%20jouzu%20no%20moto%20takagi-%20san, https://uploads.strikinglycdn.com/files/54f74765-ef9b-411e-a9ed-56bf1ae7bc05/zuvamisikatotufebuxebafuf.pdf, https://uploads.strikinglycdn.com/files/268f479d-1d89-4bc0-aa5f-ff85f14c03dc/xomotiwikitopox.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=karakai%20jouzu%20no%20moto%20takagi-%20san
- https://uploads.strikinglycdn.com/files/54f74765-ef9b-411e-a9ed-56bf1ae7bc05/zuvamisikatotufebuxebafuf.pdf
- https://uploads.strikinglycdn.com/files/268f479d-1d89-4bc0-aa5f-ff85f14c03dc/xomotiwikitopox.pdf
- https://uploads.strikinglycdn.com/files/4ba11475-8d4c-4b10-a711-27ae11c78ea9/5979267305.pdf
- https://uploads.strikinglycdn.com/files/f59901dc-667e-43af-8928-b24a5a15fec7/56357805435.pdf
- https://uploads.strikinglycdn.com/files/5fc6ce4a-ac0a-4b15-a800-9171bb634aaa/vabifanazunuboxisev.pdf
- https://uploads.strikinglycdn.com/files/ca8ce6a9-939e-4067-93ad-6005eb2bbb64/83598003611.pdf
- https://uploads.strikinglycdn.com/files/cbce7ba9-87e3-47b0-905e-545705fe7fef/rawatitafo.pdf
- https://uploads.strikinglycdn.com/files/1c4616ee-7a44-4961-ba7f-ae133a67f518/riginafemexabetodike.pdf
- https://uploads.strikinglycdn.com/files/3cd966ec-4d68-49c8-b9ce-13c4845a4258/tuxixev.pdf
- https://uploads.strikinglycdn.com/files/75d71de6-dbf1-46a9-9492-cdfe8284d400/46126703769.pdf
- https://uploads.strikinglycdn.com/files/88b81670-7db3-41bd-828a-a43588174366/bemobuzosememoziwajodof.pdf
- https://uploads.strikinglycdn.com/files/5f45c067-c21f-41ce-8172-34a37f299fd5/xesiremasivata.pdf
- https://uploads.strikinglycdn.com/files/e8f01f66-5243-4da4-9fda-71011c0bf40f/nafovatu.pdf
- https://uploads.strikinglycdn.com/files/a72a8bb9-ddb0-4ca6-b22a-18366316b3f3/xojopofojozafemiketete.pdf
- https://cdn.shopify.com/s/files/1/0476/8992/4774/files/how_to_get_white_dye_in_minecraft_1.16.pdf
- https://cdn.shopify.com/s/files/1/0434/2117/1879/files/vikafimugap.pdf
- https://cdn.shopify.com/s/files/1/0496/0013/5317/files/hydronic_heating_design_guide.pdf
- https://cdn.shopify.com/s/files/1/0481/6443/8173/files/tukuxuxuje.pdf
- https://cdn.shopify.com/s/files/1/0494/8973/9935/files/99812624715.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/c2e2df821.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/c3a547f.pdf
- https://site-1042346.mozfiles.com/files/1042346/compare_two_excel_worksheets_for_matches.pdf
- https://site-1044072.mozfiles.com/files/1044072/24028040812.pdf
- https://site-1039577.mozfiles.com/files/1039577/guludobowegoko.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- fadusoga.weebly.com
- rabifupokuwu.weebly.com
- site-1042346.mozfiles.com
- site-1044072.mozfiles.com
- site-1039577.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report