SUSPICIOUS — 99595686431.pdf
SUSPICIOUS — 99595686431.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ad8db85c948fc0504507e21bc48910d278c2f85f908d7b38081e32fbd1a543d3 - SHA-1:
a6f2bf36716de57f9967eca0dd49a1a90201bd3f - MD5:
4629cc434f6c901515f14348238daaea - ssdeep:
768:vgGzpDDpDYCRO9sgc7dMiWy6kIK3sMPWpMYkyGUVDN4lhUsvBpP:YGFfpDewpIwJPVgD4DUsvBpP - TLSH:
T11D307DF32057EC4CB68B9B47ADEB29692189C7896237D7A0448C376DC47C67E7E10920 - Submitted as: 99595686431.pdf
- File type: pdf · Size: 38728 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=daniel+julez+j.+smith+jr, https://uploads.strikinglycdn.com/files/e424bd20-9e78-4776-9704-3dd204b22885/xudegoguzom.pdf, https://uploads.strikinglycdn.com/files/ef53608d-faa2-4638-a2cd-f10f9f9fac59/zibipozij.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=daniel+julez+j.+smith+jr
- https://uploads.strikinglycdn.com/files/e424bd20-9e78-4776-9704-3dd204b22885/xudegoguzom.pdf
- https://uploads.strikinglycdn.com/files/ef53608d-faa2-4638-a2cd-f10f9f9fac59/zibipozij.pdf
- https://uploads.strikinglycdn.com/files/ea495f2d-245c-417d-ba6b-6bc568d824b6/62745662869.pdf
- https://uploads.strikinglycdn.com/files/06510002-305c-40b4-9bd0-aa82d4ac0069/10078704345.pdf
- https://uploads.strikinglycdn.com/files/d65df43f-c105-41f6-b105-78e5f7f53cfb/pibalosejijajixofel.pdf
- https://cdn.shopify.com/s/files/1/0428/9026/4742/files/best_router_bits.pdf
- https://cdn.shopify.com/s/files/1/0484/1016/5416/files/proportional_reasoning_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0436/4907/3312/files/2002_ford_mustang_gt_manual_transmission_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0434/0436/1895/files/64845077774.pdf
- https://cdn.shopify.com/s/files/1/0437/9246/6080/files/summertime_saga_computer_password.pdf
- https://site-1038529.mozfiles.com/files/1038529/14145329152.pdf
- https://site-1039656.mozfiles.com/files/1039656/86017672499.pdf
- https://site-1036716.mozfiles.com/files/1036716/55937136380.pdf
- https://site-1042271.mozfiles.com/files/1042271/67142863847.pdf
- https://site-1039307.mozfiles.com/files/1039307/pajexekorovu.pdf
- https://cdn.shopify.com/s/files/1/0438/6285/1749/files/ronerawodujud.pdf
- https://cdn.shopify.com/s/files/1/0429/7746/0383/files/4_words_answers_level_22.pdf
- https://cdn.shopify.com/s/files/1/0440/2642/9605/files/the_stupid_test_ultimatum_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0486/2912/1182/files/jurilufavi.pdf
- https://cdn.shopify.com/s/files/1/0496/2097/5767/files/pokemon_ash_gray_guide.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1038529.mozfiles.com
- site-1039656.mozfiles.com
- site-1036716.mozfiles.com
- site-1042271.mozfiles.com
- site-1039307.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report