SUSPICIOUS — ketadovaguve.pdf
SUSPICIOUS — ketadovaguve.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b921eeab80ffba31af20e1f1545cc1f362af1f8a5361cde160e33cdd57e5b11e - SHA-1:
f883fdc687389b08f9eca08075de3f8ec632b8b2 - MD5:
168d3226832a110454211bb083f00b12 - ssdeep:
768:cgGzpD6HpWb9rxUhrVO+GJm5pgS0+P6OYr07HnYY22qfYpbq2o7J8l:5GFEp4M3CODwYJq2o7J8l - TLSH:
T157318DF750E3EC4C798B9B53AEEB105A618AC38C6035AB6418C8772DC47C6BD7E10960 - Submitted as: ketadovaguve.pdf
- File type: pdf · Size: 41089 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=lowrance%20elite%203x%20dsi%20transducer, https://cdn.shopify.com/s/files/1/0433/9974/1596/files/13058893330.pdf, https://cdn.shopify.com/s/files/1/0486/5327/1208/files/descargar_hopping_ball_apk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=lowrance%20elite%203x%20dsi%20transducer
- https://cdn.shopify.com/s/files/1/0433/9974/1596/files/13058893330.pdf
- https://cdn.shopify.com/s/files/1/0486/5327/1208/files/descargar_hopping_ball_apk.pdf
- https://cdn.shopify.com/s/files/1/0485/0162/0898/files/getububo.pdf
- https://cdn.shopify.com/s/files/1/0266/8301/5342/files/85334884039.pdf
- https://cdn.shopify.com/s/files/1/0497/9307/3306/files/malada.pdf
- https://cdn.shopify.com/s/files/1/0439/1898/3323/files/21279854236.pdf
- https://cdn.shopify.com/s/files/1/0496/5629/9671/files/9799724596.pdf
- https://cdn.shopify.com/s/files/1/0498/0604/9442/files/experiment_27_the_solvent_properties_of_water_answers.pdf
- https://uploads.strikinglycdn.com/files/0ebfb923-6177-4144-8d3e-230c8e51b88b/zuladipokizutudiv.pdf
- https://uploads.strikinglycdn.com/files/fcd813ad-4de1-4361-97a1-9c5d26ac2774/fonuk.pdf
- https://uploads.strikinglycdn.com/files/523ee6cf-e80b-4ed0-8b68-7a49c7e0edc5/47351264110.pdf
- https://uploads.strikinglycdn.com/files/f8771c75-233e-44f5-92f0-2f9304b0f171/mesategowatuwapibezakaza.pdf
- https://site-1040038.mozfiles.com/files/1040038/76627185455.pdf
- https://site-1037827.mozfiles.com/files/1037827/vepivigezagidoxesuwidol.pdf
- https://uploads.strikinglycdn.com/files/e31602a3-c271-4d06-9a6c-70cc82449930/22916034329.pdf
- https://uploads.strikinglycdn.com/files/361a49d6-1437-41ff-a66d-213216d9b602/kedemovusupezamelotezipo.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f871697c2f3f.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f874bd1a75ca.pdf
- https://cdn-cms.f-static.net/uploads/4365649/normal_5f870adbe6ca6.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f8733e876688.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1040038.mozfiles.com
- site-1037827.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report