SUSPICIOUS — attila_eastern_roman_empire_guide.pdf
SUSPICIOUS — attila_eastern_roman_empire_guide.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b382fcb83e4299766cf4c8dbecfe59cb5967be8e6b2ca0d408f58df5708a5aa8 - SHA-1:
ca9429d74cc685a3b07c396ed6217ee89d78a75e - MD5:
59e7e436a94a49a40d7a1f0ba07f22cf - ssdeep:
1536:HGFQpx7xhI3Q9vqMumP2XJtxEVoxu/fx:mFQpx7HI3Q5umP2vxEVoAR - TLSH:
T1CA35BFF3155BED4CBA8B8B67ADEA214C254AD6CC6136E7B05058733CD1B86BDBE00460 - Submitted as: attila_eastern_roman_empire_guide.pdf
- File type: pdf · Size: 58179 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/pify?keyword=attila+eastern+roman+empire+guide, https://cdn.shopify.com/s/files/1/0501/0800/6565/files/rosemarie_tong_feminist_thought.pdf, https://cdn.shopify.com/s/files/1/0437/0454/9531/files/cherry_hill_fire_department_inspection.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/pify?keyword=attila+eastern+roman+empire+guide
- https://cdn.shopify.com/s/files/1/0501/0800/6565/files/rosemarie_tong_feminist_thought.pdf
- https://cdn.shopify.com/s/files/1/0437/0454/9531/files/cherry_hill_fire_department_inspection.pdf
- https://cdn.shopify.com/s/files/1/0437/9970/7805/files/52148296847.pdf
- https://cdn.shopify.com/s/files/1/0492/2864/4508/files/elephant_baby_shower_decorations_girl.pdf
- https://cdn.shopify.com/s/files/1/0497/3795/7537/files/53657424105.pdf
- https://site-1040136.mozfiles.com/files/1040136/manofebofesisiwodud.pdf
- https://uploads.strikinglycdn.com/files/a40556a0-99e5-4b95-9481-a9ccb1fd919c/61035126157.pdf
- https://uploads.strikinglycdn.com/files/a9813378-0361-4d54-ab68-7eb1c67be1ab/76408460850.pdf
- https://uploads.strikinglycdn.com/files/00088923-d975-4c86-a7b8-1685cae18982/xopiwudofitutejoloda.pdf
- https://uploads.strikinglycdn.com/files/59e4882e-ee6b-40cd-a728-793b90dad64e/milinavuzotugul.pdf
- https://site-1040100.mozfiles.com/files/1040100/50134492185.pdf
- https://site-1039811.mozfiles.com/files/1039811/70901951979.pdf
- https://site-1042102.mozfiles.com/files/1042102/20326027056.pdf
- https://site-1038759.mozfiles.com/files/1038759/kixefegopabu.pdf
- https://site-1036973.mozfiles.com/files/1036973/41493480010.pdf
- https://site-1048194.mozfiles.com/files/1048194/penediwamirod.pdf
- https://site-1042834.mozfiles.com/files/1042834/lefeli.pdf
- https://site-1041286.mozfiles.com/files/1041286/49515924372.pdf
- https://site-1044067.mozfiles.com/files/1044067/lifetefunidafixekuluw.pdf
- https://site-1043646.mozfiles.com/files/1043646/tesiwagepukumejetex.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1040136.mozfiles.com
- uploads.strikinglycdn.com
- site-1040100.mozfiles.com
- site-1039811.mozfiles.com
- site-1042102.mozfiles.com
- site-1038759.mozfiles.com
- site-1036973.mozfiles.com
- site-1048194.mozfiles.com
- site-1042834.mozfiles.com
- site-1041286.mozfiles.com
- site-1044067.mozfiles.com
- site-1043646.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report