SUSPICIOUS — mabiraj.pdf
SUSPICIOUS — mabiraj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c0be78a09dbebae8e050d4ad4ab59671df5eb0e60297947f3a4bc59bd06b1eaf - SHA-1:
37157d4c6e9cc5a75cb89316a5a48b1b03618b6b - MD5:
296712497532a0ebaff33ccd3fe818c3 - ssdeep:
768:sgGzpDgeSPMrVBu9EtWdudc2I05WQulFmy4+F/nHZyJQUwU6UyWdPO/BFCVW+UYF:pGFEeHWQuLpF/nQJMU6UyWsFgpUYF - TLSH:
T1A8338EF310ABED8C3B8AAF03A9AF1159604BC74921329B60454C7B2CD57C9BE7F10A15 - Submitted as: mabiraj.pdf
- File type: pdf · Size: 48242 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=nino%20schembri%20brazilian%20jiu%20jitsu, https://cdn-cms.f-static.net/uploads/4369766/normal_5f88a2597384e.pdf, https://cdn-cms.f-static.net/uploads/4369502/normal_5f88faecf319c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=nino%20schembri%20brazilian%20jiu%20jitsu
- https://cdn-cms.f-static.net/uploads/4369766/normal_5f88a2597384e.pdf
- https://cdn-cms.f-static.net/uploads/4369502/normal_5f88faecf319c.pdf
- https://cdn-cms.f-static.net/uploads/4366364/normal_5f876c68d6bb9.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f870d027c9b4.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f876e145cf66.pdf
- https://cdn.shopify.com/s/files/1/0502/3937/3477/files/snack_sign_up_sheet_template_free.pdf
- https://cdn.shopify.com/s/files/1/0437/3551/5290/files/unit_1_basic_economic_concepts_answers.pdf
- https://cdn.shopify.com/s/files/1/0432/1830/5179/files/48100471964.pdf
- https://uploads.strikinglycdn.com/files/e9f2808f-15c0-4af9-9db7-f53e3f5fb3c5/dutugalu.pdf
- https://uploads.strikinglycdn.com/files/68fb3630-9f29-4b47-923e-359c074a2abe/zapofivekaradoji.pdf
- https://cdn.shopify.com/s/files/1/0481/4097/6291/files/30661507070.pdf
- https://cdn.shopify.com/s/files/1/0486/4589/8408/files/news_broadcast_script_english.pdf
- https://cdn.shopify.com/s/files/1/0437/3915/2535/files/24383119427.pdf
- https://cdn.shopify.com/s/files/1/0432/8118/6972/files/ragojamenaf.pdf
- https://cdn.shopify.com/s/files/1/0437/9561/1809/files/onkyo_tx-nr585_problems.pdf
- https://cdn.shopify.com/s/files/1/0499/8837/0582/files/17723381229.pdf
- https://cdn.shopify.com/s/files/1/0433/6055/1070/files/how_to_make_holy_water_joke.pdf
- https://cdn.shopify.com/s/files/1/0431/5221/2130/files/robbery_bob_apk_download_uptodown.pdf
- https://cdn.shopify.com/s/files/1/0481/5644/2777/files/kubodit.pdf
- https://rijizego.weebly.com/uploads/1/3/0/7/130776487/775cd489.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/6977354.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- rijizego.weebly.com
- kelobutino.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report