SUSPICIOUS — ca654e6035f2be.pdf
SUSPICIOUS — ca654e6035f2be.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b9b9fa6983c7c927b52a95cbe0cb8dc961850d7d4473fbd41c3bea400870040e - SHA-1:
159e43e1ba01a35a26772499f72a613a8e42e73f - MD5:
a630053371a61e055d3300a473c2e478 - ssdeep:
1536:OGFipuuXdl7y/gOq5IG9j8WOKXCU8QdwCY:3Fipxdl7YTkQPKXj3S - TLSH:
T11535AFF71097ED8C3A8F5B439FEB01596046D6896123A7A0418C7B2CC57C2FD2F106A5 - Submitted as: ca654e6035f2be.pdf
- File type: pdf · Size: 60572 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=pathfinder%20hell%20unleashed%20pdf%20download, https://uploads.strikinglycdn.com/files/3b5e39a1-39c2-4dd8-91c9-677d3a4668e9/bukoxasezozozoxumomaju.pdf, https://uploads.strikinglycdn.com/files/0a0a72c4-0bb8-47be-bf51-c628baccbe4c/duvedesawotafejorivu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=pathfinder%20hell%20unleashed%20pdf%20download
- https://uploads.strikinglycdn.com/files/3b5e39a1-39c2-4dd8-91c9-677d3a4668e9/bukoxasezozozoxumomaju.pdf
- https://uploads.strikinglycdn.com/files/0a0a72c4-0bb8-47be-bf51-c628baccbe4c/duvedesawotafejorivu.pdf
- https://uploads.strikinglycdn.com/files/a2b1b4fa-553e-412b-aad3-a778ab8e58f0/povujirejanul.pdf
- https://uploads.strikinglycdn.com/files/3b809454-e8f8-41d4-9b0c-63d5f052eb28/34493314302.pdf
- https://uploads.strikinglycdn.com/files/3c08cb7f-fc60-47d4-8784-fbe2b554b26c/zinizelurosilivuri.pdf
- https://uploads.strikinglycdn.com/files/d3fdd874-be43-4f5a-928d-9fafbeac9856/radapunafafopa.pdf
- https://uploads.strikinglycdn.com/files/81b879fe-6762-4875-87c3-db19b8ae0b42/75359457612.pdf
- https://uploads.strikinglycdn.com/files/56fcb6da-79ef-49c6-9d29-351fd1bd0355/39040855053.pdf
- https://uploads.strikinglycdn.com/files/6ba9c7b0-e58a-4d3f-a511-1635cac6249f/61268559403.pdf
- https://uploads.strikinglycdn.com/files/e2154b3e-2fd6-4a40-b65b-41ad7544905f/zepowaw.pdf
- https://uploads.strikinglycdn.com/files/b8e10838-82ca-4d9f-8282-bf66cbc3841e/55168065121.pdf
- https://uploads.strikinglycdn.com/files/214457f7-f7b2-487a-aa53-bfb99912f3c8/zezubezejadijilijafivemis.pdf
- https://uploads.strikinglycdn.com/files/93499cba-e78e-428c-bbad-13a920026a35/nigaxoxiditelasu.pdf
- https://uploads.strikinglycdn.com/files/a14c055b-3563-4b04-b96d-b4707da6c03f/gegafesipugexidegovopax.pdf
- https://uploads.strikinglycdn.com/files/6c81d114-6bfd-481b-b739-845b7663819c/anais_nin.pdf
- https://cdn-cms.f-static.net/uploads/4384633/normal_5f8c4b4050488.pdf
- https://cdn-cms.f-static.net/uploads/4366633/normal_5f87e63113cec.pdf
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f8f362dc975c.pdf
- https://cdn-cms.f-static.net/uploads/4381978/normal_5f8cc49adce8f.pdf
- https://cdn-cms.f-static.net/uploads/4393901/normal_5f8ec0a818332.pdf
- https://cdn.shopify.com/s/files/1/0485/7040/0928/files/24255034469.pdf
- https://cdn.shopify.com/s/files/1/0504/4450/1161/files/86338485256.pdf
- https://cdn.shopify.com/s/files/1/0436/3865/3086/files/empirical_formula_of_a_hydrate_lab_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0501/7029/8523/files/17782661610.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report