SUSPICIOUS — 1766028.pdf
SUSPICIOUS — 1766028.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
acb6f305feaf17e6c39c4e1f3c83ef239d5ac276741940d6a0f4d5e7849d7336 - SHA-1:
7856d00e252d36780aee48eaf53b79b5e5e1b5ea - MD5:
9b9fc30c11f072d336746a9419e5fdeb - ssdeep:
768:0gGzpDVe6bAaxj2iPbEt4YXs4m0uBdS9rYMpELBmkpmgddIKoTet3uH/xbEBJzym:BGFhe6c0KiwXs4Hbr+mWdNLs4Jn9B5 - TLSH:
T184347CE310A3EC8C7A8F6B43ADAB00AD614AD7897132E7A045C8672DC57C6FD6F10561 - Submitted as: 1766028.pdf
- File type: pdf · Size: 55162 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ups%20driver%20salary%20florida, https://site-1042937.mozfiles.com/files/1042937/demanixoru.pdf, https://site-1041779.mozfiles.com/files/1041779/kobegogukagodisoxedax.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ups%20driver%20salary%20florida
- https://site-1042937.mozfiles.com/files/1042937/demanixoru.pdf
- https://site-1041779.mozfiles.com/files/1041779/kobegogukagodisoxedax.pdf
- https://site-1039487.mozfiles.com/files/1039487/taveleveru.pdf
- https://uploads.strikinglycdn.com/files/b6c7a857-fa7a-4077-bc3b-413150c69dcf/90338673643.pdf
- https://uploads.strikinglycdn.com/files/99d049b4-27d5-4324-bac2-8ca3854ed705/22764352641.pdf
- https://uploads.strikinglycdn.com/files/339dd68c-e8a5-4d47-aa82-f6032f4d78ed/gerepakaw.pdf
- https://uploads.strikinglycdn.com/files/43b34930-336c-4abe-a6fc-a02e59849d83/bopilivowenobibatotan.pdf
- https://uploads.strikinglycdn.com/files/8a522fe1-2a10-4710-8866-a4e88fec5788/doxafekenetukogigopa.pdf
- https://uploads.strikinglycdn.com/files/da3b7e55-b886-456e-95c0-654fd4bd3d2d/32028983556.pdf
- https://uploads.strikinglycdn.com/files/d27c529c-db41-45c3-b559-bf549558e2c4/50959579201.pdf
- https://uploads.strikinglycdn.com/files/5262be6f-64c7-4a1f-a9e0-12878abea409/18427273247.pdf
- https://uploads.strikinglycdn.com/files/9dc485e6-e78a-4192-89cb-7a6979d53458/36036169716.pdf
- https://cdn.shopify.com/s/files/1/0482/4232/7713/files/jumewejomanapebab.pdf
- https://cdn.shopify.com/s/files/1/0438/6373/6485/files/old_world_language_families.pdf
- https://cdn.shopify.com/s/files/1/0428/2574/4540/files/4383883883.pdf
- https://cdn.shopify.com/s/files/1/0483/7847/8743/files/55967011561.pdf
- https://cdn.shopify.com/s/files/1/0477/5664/0412/files/76311425023.pdf
- https://uploads.strikinglycdn.com/files/b9a9b78e-8505-4d44-9933-1e7927e310f8/31145489046.pdf
- https://uploads.strikinglycdn.com/files/041e0945-23bf-422e-9010-43128f0f05e8/rulegu.pdf
- https://uploads.strikinglycdn.com/files/7cbb7ffa-2a99-4510-847b-78f289217b39/49434304670.pdf
- https://uploads.strikinglycdn.com/files/fdafe5d6-3d64-4e80-95e8-639f14895eb4/gupux.pdf
- https://uploads.strikinglycdn.com/files/212cfd18-cb5c-4a71-9611-7afa9e4feb73/33411869603.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f8701d080cf9.pdf
- https://cdn-cms.f-static.net/uploads/4366024/normal_5f873887e9dd5.pdf
Embedded domains
- gettraff.ru
- site-1042937.mozfiles.com
- site-1041779.mozfiles.com
- site-1039487.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report