SUSPICIOUS — devamet-derekaw.pdf
SUSPICIOUS — devamet-derekaw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c900bba085f4271115fc81887442e993cdaa3e03c5c41b837c32c23d519091b9 - SHA-1:
bf476d8f7533fe0512709bb06b078fdb7f8e2a50 - MD5:
3bdd3bb0c5b12aff11476b2086791ca3 - ssdeep:
768:6gGzpD3paAoBBRS+gHfUICXqbRuJvQkhWD3NKjccREXegivvN0IgUe6Y3Vr5Kz+T:nGFDpaAdIPWDkjccREXegivKIgT39mH8 - TLSH:
T15C33AEF3505BEC9CBA869F13ACAA0068714DC7896272E770588D367DD4BC2BD6E10C61 - Submitted as: devamet-derekaw.pdf
- File type: pdf · Size: 47825 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=can%20you%20checkmate%20while%20in%20check, https://uploads.strikinglycdn.com/files/c5bc78a3-c4ef-4589-abdb-c0178ab3c779/duvisimotowugisozapiselin.pdf, https://uploads.strikinglycdn.com/files/f186cc7f-d89f-47bf-b2dc-85f7762b3dbe/baby_driver_theater.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=can%20you%20checkmate%20while%20in%20check
- https://uploads.strikinglycdn.com/files/c5bc78a3-c4ef-4589-abdb-c0178ab3c779/duvisimotowugisozapiselin.pdf
- https://uploads.strikinglycdn.com/files/f186cc7f-d89f-47bf-b2dc-85f7762b3dbe/baby_driver_theater.pdf
- https://uploads.strikinglycdn.com/files/1b5e3bd5-69dc-4b85-98eb-1496915ba5d4/19597503636.pdf
- https://cdn-cms.f-static.net/uploads/4379848/normal_5f8bf60d68b87.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f87d9f49b6b8.pdf
- https://cdn-cms.f-static.net/uploads/4384155/normal_5f8e116658bcc.pdf
- https://cdn-cms.f-static.net/uploads/4368242/normal_5f8cb19929dc3.pdf
- https://cdn-cms.f-static.net/uploads/4385202/normal_5f8c470587fab.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f86fa4e2dd23.pdf
- https://cdn-cms.f-static.net/uploads/4373259/normal_5f8af808ca856.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f87ec1eee2be.pdf
- https://uploads.strikinglycdn.com/files/4947e042-0497-40f8-9cae-5871eb765dfe/sajobuvazubugeziwefenam.pdf
- https://uploads.strikinglycdn.com/files/fb9440f3-801b-4440-9436-b7e3016bda5a/gukebuk.pdf
- https://cdn.shopify.com/s/files/1/0432/8167/8494/files/circle_of_lights_minnesota.pdf
- https://cdn.shopify.com/s/files/1/0433/3433/6670/files/75768349029.pdf
- https://cdn.shopify.com/s/files/1/0499/2430/9160/files/xawuwul.pdf
- https://cdn.shopify.com/s/files/1/0434/4361/7958/files/58438837418.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- e.in
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report