SUSPICIOUS — 3c99f7.pdf
SUSPICIOUS — 3c99f7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b11e75697badfa57e4cb1c86118a6c0ee300c6daffc1c7ea40da9d8e8df389d9 - SHA-1:
e2e2de9df54eee1fa014e3bec18e94b2c327b5b6 - MD5:
727879e17b4f707387b416f08f4d9d05 - ssdeep:
768:fgGzpDgeWiVG31H+qDGhitWSXobUijL3pYHOT5EZQh7vPCuVEbyb0f7:oGF8ecDwvYuKZYquVEm0f7 - TLSH:
T148326CF310A3ED8C7A8F6B43AEA715996086C6487132D750458CB72CC57CAED3F10AA1 - Submitted as: 3c99f7.pdf
- File type: pdf · Size: 44085 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=pokemon%20heartgold%20nintendo%20ds, https://uploads.strikinglycdn.com/files/19c884a7-7024-410b-91f2-1baa14c24b88/57418996289.pdf, https://uploads.strikinglycdn.com/files/1c4db443-2286-4926-864e-3c07d7fe3daa/wabapinimugalewimofojagu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=pokemon%20heartgold%20nintendo%20ds
- https://uploads.strikinglycdn.com/files/19c884a7-7024-410b-91f2-1baa14c24b88/57418996289.pdf
- https://uploads.strikinglycdn.com/files/1c4db443-2286-4926-864e-3c07d7fe3daa/wabapinimugalewimofojagu.pdf
- https://uploads.strikinglycdn.com/files/f9c513b6-341f-43d6-9487-eef78cb09a46/duritumonesogigono.pdf
- https://uploads.strikinglycdn.com/files/02beb224-43dc-4f26-9672-24af86c346ff/55783763632.pdf
- https://uploads.strikinglycdn.com/files/3df72766-4c9b-415f-ac63-c241026ee3db/todubesinuvimadibulegage.pdf
- https://uploads.strikinglycdn.com/files/8e6dce39-32f1-42b7-add6-33598e1d8983/31513579455.pdf
- https://uploads.strikinglycdn.com/files/3bb3636d-65b0-4692-a694-3f4cd4954e51/bexuxidipenoxarodabofofut.pdf
- https://uploads.strikinglycdn.com/files/ab663f1c-a354-4df8-94d9-c60e0209f81a/kixenoxixa.pdf
- https://uploads.strikinglycdn.com/files/551a2b4f-cc3c-49cc-add0-78f2ee05d925/wexifamusom.pdf
- https://uploads.strikinglycdn.com/files/567ad491-33fc-4ac3-969f-fc2f7fd42291/lubusiviboguz.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/xopevu_vilugarokobijos_fimorekon.pdf
- https://virataxutepubom.weebly.com/uploads/1/3/0/8/130874282/9596081.pdf
- https://kenilajapa.weebly.com/uploads/1/3/1/0/131069910/liwerono.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/4106527.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/tomefifi.pdf
- https://jubunukaf.weebly.com/uploads/1/3/1/4/131483214/7af8ed.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/nidisetati.pdf
- https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/553845.pdf
- https://cdn.shopify.com/s/files/1/0432/2908/5859/files/jazipi.pdf
- https://cdn.shopify.com/s/files/1/0482/9282/3204/files/37151447457.pdf
- https://cdn.shopify.com/s/files/1/0503/7247/7115/files/28493524155.pdf
- https://cdn.shopify.com/s/files/1/0502/2983/7982/files/visitor_questionnaire_cdcr_form_106.pdf
- https://cdn.shopify.com/s/files/1/0436/5742/9145/files/juvazef.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- jawasolasazilem.weebly.com
- virataxutepubom.weebly.com
- kenilajapa.weebly.com
- fijojonibiw.weebly.com
- dirigesibujov.weebly.com
- jubunukaf.weebly.com
- dutitujazekap.weebly.com
- rabugotekinevod.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report