SUSPICIOUS — 61986333155.pdf
SUSPICIOUS — 61986333155.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b05badb6c02e40eb3637ed394d4ab96f4a4af163af40241f9663b72bc5576841 - SHA-1:
abc070ec127367244764539ba98b967e7740f8e7 - MD5:
fbfd3b7821a503e3229a2606664fd0fe - ssdeep:
1536:SGFQBOR8ZUsBLa9dRwlcpuGNWXYKcIjUv:LFQBORiU0LaDOcIGuiIU - TLSH:
T17F33AFF31097EC4CA6C6AB43A9F21089710AD7883236C7A054987B6DD8BC67E6F50A51 - Submitted as: 61986333155.pdf
- File type: pdf · Size: 49683 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=elementary+calculus+textbook+pdf, https://uploads.strikinglycdn.com/files/3ad4fee0-8e38-465c-8a5d-e7315341d63d/54681693770.pdf, https://uploads.strikinglycdn.com/files/c999c1e1-0e48-4f69-a4b8-e8e64a78329e/22382816952.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=elementary+calculus+textbook+pdf
- https://uploads.strikinglycdn.com/files/3ad4fee0-8e38-465c-8a5d-e7315341d63d/54681693770.pdf
- https://uploads.strikinglycdn.com/files/c999c1e1-0e48-4f69-a4b8-e8e64a78329e/22382816952.pdf
- https://uploads.strikinglycdn.com/files/627dd19e-e2b8-4335-aa68-3eb73c956da4/74153600988.pdf
- https://uploads.strikinglycdn.com/files/def5fb80-ed45-4b63-9cf9-2c6383ff03e4/xokefizexikavazewewi.pdf
- https://uploads.strikinglycdn.com/files/4a1c102f-bb23-4707-8a39-8abc7120062c/togogivovudibimad.pdf
- https://uploads.strikinglycdn.com/files/bd0ebad0-34b5-4e3f-b9b5-3b1d238949b2/jipogugawazujabetu.pdf
- https://uploads.strikinglycdn.com/files/54e46736-d76e-400e-a7f1-f76d99a6a564/16106961597.pdf
- https://uploads.strikinglycdn.com/files/3a80bce1-a90a-4c18-b30d-0a8eedc77c73/31728477447.pdf
- https://uploads.strikinglycdn.com/files/1cf04c9f-c8f7-4833-ae79-ef89bd2dfe14/46680755954.pdf
- https://uploads.strikinglycdn.com/files/fc849858-09cf-4dff-93ba-bd19c2551b31/52862995402.pdf
- https://uploads.strikinglycdn.com/files/f1d47e07-5d9d-4dff-a1e3-825fdfb915c3/vekojudagaxixolefotexos.pdf
- https://uploads.strikinglycdn.com/files/9774fb47-3259-42e6-a980-9b2359c34f16/gusajufojides.pdf
- https://cdn.shopify.com/s/files/1/0482/9393/7316/files/vufup.pdf
- https://cdn.shopify.com/s/files/1/0484/0488/9758/files/58280152613.pdf
- https://cdn.shopify.com/s/files/1/0480/2209/3983/files/51369058577.pdf
- https://cdn.shopify.com/s/files/1/0479/3722/4860/files/solutions_manual_for_database_systems_the_complete_book_2_e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report