SUSPICIOUS — 3115137.pdf
SUSPICIOUS — 3115137.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ba4a2580ede83e33cfc3afdae372ad6e50a163f561406f30cd41a38ddff30007 - SHA-1:
4568e4fe9155336e2d8b72e97527b54e1940e2e9 - MD5:
a33cf5cd3af2f978a71d3ed7a132c945 - ssdeep:
768:agGzpD5Ce8e6v8AU0bdwI/pQxOV0MK4B9N4kIR+6z+ctXlPWluIes:HGFVCe8aboq4XNM+6qcplPGuIes - TLSH:
T1CE318DF3506BDD8CBB8B9B13ACBB1125114E974D22329B9415CC772CC4BCAADAF10961 - Submitted as: 3115137.pdf
- File type: pdf · Size: 42264 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=jumble%20sales%20essex, https://cdn-cms.f-static.net/uploads/4368248/normal_5f8bc2adc69f1.pdf, https://cdn-cms.f-static.net/uploads/4366312/normal_5f87e287adf53.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=jumble%20sales%20essex
- https://cdn-cms.f-static.net/uploads/4368248/normal_5f8bc2adc69f1.pdf
- https://cdn-cms.f-static.net/uploads/4366312/normal_5f87e287adf53.pdf
- https://cdn-cms.f-static.net/uploads/4368500/normal_5f8893921621f.pdf
- https://cdn-cms.f-static.net/uploads/4366346/normal_5f887607204d3.pdf
- https://uploads.strikinglycdn.com/files/92433d4d-ecc4-4ab5-9319-9cd3a7dde08e/mifovesawosowenip.pdf
- https://uploads.strikinglycdn.com/files/583573f7-1f34-4da5-8c80-ed45408d7533/zuronowekexijemudanutagu.pdf
- https://uploads.strikinglycdn.com/files/41da48f3-5efb-449b-96b0-27b913a577ff/dupesanowajidofig.pdf
- https://cdn-cms.f-static.net/uploads/4369187/normal_5f8920201d185.pdf
- https://cdn-cms.f-static.net/uploads/4386084/normal_5f8cc76090eb6.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f873a4490abb.pdf
- https://cdn-cms.f-static.net/uploads/4366321/normal_5f8919ff426cf.pdf
- https://uploads.strikinglycdn.com/files/89dfb5c0-d598-4f8f-be00-059d043a0c5e/46369218540.pdf
- https://uploads.strikinglycdn.com/files/4d9d24d8-4ac4-403b-b9a4-1f3e0fdd7932/76388166196.pdf
- https://uploads.strikinglycdn.com/files/670479f9-2569-4185-9b94-414f2f02fd50/loxotunesijovaxuzudug.pdf
- https://cdn-cms.f-static.net/uploads/4384471/normal_5f8cbb5a2fcdf.pdf
- https://cdn-cms.f-static.net/uploads/4367289/normal_5f873df5a5a5e.pdf
- https://cdn-cms.f-static.net/uploads/4369143/normal_5f881dc036ec9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report