SUSPICIOUS — 2f2e24e5.pdf
SUSPICIOUS — 2f2e24e5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
be203da075593335ffbf45ccfe8b410953aa7274aa019dd9f99e26cc24c5f68f - SHA-1:
36428dcd89ab1501222624f8f5eec5361ae0e94c - MD5:
037022f39ce102e10767ef7a3162a7cf - ssdeep:
1536:8GFEpD1GoCkTy7Tpe6gnK2wK9MCh0TVmRJzYgQo:ZFEpxEkSW9MChuVqJzYc - TLSH:
T136338EF340A3ED4CBB8B9B436DFB20A9558AC789513797908998366CC47C6BC7E10970 - Submitted as: 2f2e24e5.pdf
- File type: pdf · Size: 50911 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=duel%20links%20red%20eyes%20deck, https://cdn.shopify.com/s/files/1/0504/0698/1830/files/merizanawusi.pdf, https://cdn.shopify.com/s/files/1/0496/0711/4919/files/61405606258.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=duel%20links%20red%20eyes%20deck
- https://cdn.shopify.com/s/files/1/0504/0698/1830/files/merizanawusi.pdf
- https://cdn.shopify.com/s/files/1/0496/0711/4919/files/61405606258.pdf
- https://cdn.shopify.com/s/files/1/0484/2107/7144/files/91422217900.pdf
- https://site-1043373.mozfiles.com/files/1043373/zanivodu.pdf
- https://site-1036675.mozfiles.com/files/1036675/nubamopelulojemudofum.pdf
- https://site-1038572.mozfiles.com/files/1038572/58141555326.pdf
- https://cdn.shopify.com/s/files/1/0500/5692/1256/files/ions_and_subatomic_particles_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0439/0728/5147/files/79822903960.pdf
- https://cdn.shopify.com/s/files/1/0431/1751/0818/files/linear_function_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0484/2730/3080/files/kozeresapurofixiwosujiwa.pdf
- https://site-1040426.mozfiles.com/files/1040426/foreign_policy_analysis_new_approaches.pdf
- https://site-1040683.mozfiles.com/files/1040683/rozositapika.pdf
- https://site-1040354.mozfiles.com/files/1040354/keforejuvonogo.pdf
- https://site-1037192.mozfiles.com/files/1037192/gategumiveka.pdf
- https://site-1038351.mozfiles.com/files/1038351/vawuresozirometuravog.pdf
- https://site-1036824.mozfiles.com/files/1036824/foradib.pdf
- https://site-1040005.mozfiles.com/files/1040005/xusuwujepidel.pdf
- https://site-1039797.mozfiles.com/files/1039797/47816449130.pdf
- https://site-1038460.mozfiles.com/files/1038460/ritatarazisomukagibovebu.pdf
- https://site-1039427.mozfiles.com/files/1039427/54293068234.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/lanadez.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/4643970e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1043373.mozfiles.com
- site-1036675.mozfiles.com
- site-1038572.mozfiles.com
- site-1040426.mozfiles.com
- site-1040683.mozfiles.com
- site-1040354.mozfiles.com
- site-1037192.mozfiles.com
- site-1038351.mozfiles.com
- site-1036824.mozfiles.com
- site-1040005.mozfiles.com
- site-1039797.mozfiles.com
- site-1038460.mozfiles.com
- site-1039427.mozfiles.com
- guwomenod.weebly.com
- megadezatesaram.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report