SUSPICIOUS — 29692703908.pdf
SUSPICIOUS — 29692703908.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c20b54fc244b02119f78131f3ba757b7068aba0e60a3ca85481667dc8f3cb806 - SHA-1:
9a8d47de64af4085da5e52cdadf8075ff2322aae - MD5:
6291d5b15272072d8fdc9da42e69dbae - ssdeep:
768:TgGzpDtpDG4vFyaUxq0akowC1cZIvJPsPWqJ/Qqt4gPL1mwGll7iyJaavOspL:sGFBpxWZvC1cZmO/rz1mwS2yJ9OspL - TLSH:
T1D4328CF31163ED4C7A8A6F47AEAB119D6189C78C61239260A4CC37ACD07C6FD7E10961 - Submitted as: 29692703908.pdf
- File type: pdf · Size: 43805 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=2016+dinghy+towing+guide, https://site-1036883.mozfiles.com/files/1036883/76380039372.pdf, https://site-1038341.mozfiles.com/files/1038341/zobuvumugakoz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=2016+dinghy+towing+guide
- https://site-1036883.mozfiles.com/files/1036883/76380039372.pdf
- https://site-1038341.mozfiles.com/files/1038341/zobuvumugakoz.pdf
- https://site-1044017.mozfiles.com/files/1044017/42415047481.pdf
- https://site-1040101.mozfiles.com/files/1040101/rowekimezavatodomagom.pdf
- https://site-1040200.mozfiles.com/files/1040200/nesijanexo.pdf
- https://cdn.shopify.com/s/files/1/0477/5352/7452/files/55826642847.pdf
- https://cdn.shopify.com/s/files/1/0484/7127/7718/files/bebizo.pdf
- https://cdn.shopify.com/s/files/1/0431/8789/6488/files/tuzolumetorokajosiw.pdf
- https://cdn.shopify.com/s/files/1/0432/7568/1947/files/37545204837.pdf
- https://cdn.shopify.com/s/files/1/0432/9039/4788/files/sojesevoxipafegelu.pdf
- https://uploads.strikinglycdn.com/files/66a60b28-136d-4b33-9cef-d91538e9dfdd/59503678362.pdf
- https://uploads.strikinglycdn.com/files/4251aaa4-5ce4-4904-a0cc-647accf76bff/36880142048.pdf
- https://uploads.strikinglycdn.com/files/9161330b-89ab-4c1e-b8fa-1c9777e4262a/15482168559.pdf
- https://uploads.strikinglycdn.com/files/150ba16b-4a6f-4f31-849d-053242becb1e/87962363760.pdf
- https://uploads.strikinglycdn.com/files/d0cdde16-f626-42ee-97e5-6d279b0a2b65/nitelegu.pdf
- https://site-1038460.mozfiles.com/files/1038460/nutajedariribew.pdf
- https://site-1042987.mozfiles.com/files/1042987/jasijajefujosemup.pdf
- https://site-1039896.mozfiles.com/files/1039896/mivijevexodivoposof.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036883.mozfiles.com
- site-1038341.mozfiles.com
- site-1044017.mozfiles.com
- site-1040101.mozfiles.com
- site-1040200.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1038460.mozfiles.com
- site-1042987.mozfiles.com
- site-1039896.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report