SUSPICIOUS — 81864218720.pdf
SUSPICIOUS — 81864218720.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b628eb7f7c7c05cc4df3dfedbc09fa50c75bbd5261ab7dd69cf904741bb8d983 - SHA-1:
943c49585d0c0ce1a57a08b59b9446c88b43bdcb - MD5:
7dd5d4a312b8f6505773df4655392fc4 - ssdeep:
768:KgGzpD9S5yT8koMkz0tAZWOtlVlZ70aJM8Q+ePtKXoDttaQ/GxxquPQvJB6/hYSP:XGFZSo6W+VL7LMQe4k/Gxxqtb6pYEF - TLSH:
T10433AFF710A3DD8D7ACBAB03ADAA105A114AD6CC2136E75049CD7B6CC07C9FCAE10961 - Submitted as: 81864218720.pdf
- File type: pdf · Size: 49174 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=encyclopedia+dictionary+pdf, https://uploads.strikinglycdn.com/files/35b6883f-ef0d-49c4-b27a-665e4227ab18/62172458968.pdf, https://uploads.strikinglycdn.com/files/62e1bee1-3785-4b9f-add3-ea132fe8fcdd/gixiwamijupemugitorawavaj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=encyclopedia+dictionary+pdf
- https://uploads.strikinglycdn.com/files/35b6883f-ef0d-49c4-b27a-665e4227ab18/62172458968.pdf
- https://uploads.strikinglycdn.com/files/62e1bee1-3785-4b9f-add3-ea132fe8fcdd/gixiwamijupemugitorawavaj.pdf
- https://uploads.strikinglycdn.com/files/d584be29-369f-47cd-8677-57ceb674597b/14899455932.pdf
- https://uploads.strikinglycdn.com/files/f976a12c-e243-4256-bfe6-2ef183d56fe1/rirezixulawigerepez.pdf
- https://uploads.strikinglycdn.com/files/4ff4ec3a-3e26-4fea-92c7-89ff439cafdb/sibusuzobugivofijiwip.pdf
- https://cdn.shopify.com/s/files/1/0432/9367/1590/files/computer_hardware_and_software_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0438/4319/0944/files/68963303284.pdf
- https://cdn.shopify.com/s/files/1/0430/6799/8362/files/variable_types_in_java.pdf
- https://cdn.shopify.com/s/files/1/0444/2108/7398/files/loliwovi.pdf
- https://cdn.shopify.com/s/files/1/0439/1672/2331/files/pugip.pdf
- https://uploads.strikinglycdn.com/files/949c2a7e-5ba9-4abc-a4ba-47bd14288a32/jusewododazikemosiz.pdf
- https://uploads.strikinglycdn.com/files/49fd8971-9b07-4b68-ba5f-6d4111c38b7e/99196120299.pdf
- https://uploads.strikinglycdn.com/files/ddcc1228-93f3-4577-895a-fa95df53f646/vuwusoxufididubovarone.pdf
- https://uploads.strikinglycdn.com/files/47f91d21-cd2f-492b-b20a-3e333b34c15c/57054726046.pdf
- https://cdn.shopify.com/s/files/1/0441/1500/1496/files/84590487332.pdf
- https://cdn.shopify.com/s/files/1/0428/6126/5062/files/54787790577.pdf
- https://cdn.shopify.com/s/files/1/0428/2987/3318/files/38832962.pdf
- https://cdn.shopify.com/s/files/1/0437/2883/0625/files/husky_pressure_washer_wand.pdf
- https://cdn.shopify.com/s/files/1/0463/1756/8157/files/dininukofu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- engage.aapos.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report