SUSPICIOUS — 4499465.pdf
SUSPICIOUS — 4499465.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c93d5604c312cdd959ae4f8e31a4321ef824a2196418b9844d20d0fb471197b5 - SHA-1:
0eb9ed0cfd12aadd52baedae61557c62337dc5b3 - MD5:
d2dbe82944d8fd17571b7ec98d2a3b5a - ssdeep:
768:HgGzpDVpXRwDLQyZ7iFSA00vNZ9PAfjcju2t/XPFqLTV:AGF5px001yfO/X9qLTV - TLSH:
T173328DF340A7ED4CBD86AB53ADAE2529108AC7886137974044ECE76DE07C7BDAF10851 - Submitted as: 4499465.pdf
- File type: pdf · Size: 44671 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=digimon%20world%202003%20guide, https://uploads.strikinglycdn.com/files/5739656a-6032-4122-946b-273c1970ccdc/77253051135.pdf, https://uploads.strikinglycdn.com/files/ee2697ec-7946-42b5-9c0f-461060762192/wanezexoxar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=digimon%20world%202003%20guide
- https://uploads.strikinglycdn.com/files/5739656a-6032-4122-946b-273c1970ccdc/77253051135.pdf
- https://uploads.strikinglycdn.com/files/ee2697ec-7946-42b5-9c0f-461060762192/wanezexoxar.pdf
- https://uploads.strikinglycdn.com/files/9b59d3e9-07c5-49b0-b55b-047d092f43ca/76286592543.pdf
- https://site-1042677.mozfiles.com/files/1042677/mapowalakafibusi.pdf
- https://site-1042345.mozfiles.com/files/1042345/futazesavuxigisibabezowe.pdf
- https://site-1044300.mozfiles.com/files/1044300/lutizibixidotakenesuxi.pdf
- https://site-1048221.mozfiles.com/files/1048221/13656036798.pdf
- https://uploads.strikinglycdn.com/files/8c12ea6e-83eb-4892-a2e1-ae71e60cba40/mebanuliketo.pdf
- https://uploads.strikinglycdn.com/files/7528557c-272f-4e90-b6af-bb4fd5426d95/vozonu.pdf
- https://uploads.strikinglycdn.com/files/c5620ed9-b4d4-4ae3-8277-37b9f5c92d31/85030046938.pdf
- https://uploads.strikinglycdn.com/files/6a6ea249-915f-4841-9c85-ff4b69dd153b/60976858513.pdf
- https://uploads.strikinglycdn.com/files/b9461371-8bad-4998-8e47-c130b4afe5d0/61526309985.pdf
- https://uploads.strikinglycdn.com/files/a8a561d8-63bc-49c2-893f-23c501354eb3/4683640051.pdf
- https://uploads.strikinglycdn.com/files/56a2617a-5e02-457e-bd75-e7b66c8bc582/79627157200.pdf
- https://cdn.shopify.com/s/files/1/0480/8353/3981/files/92270859759.pdf
- https://cdn.shopify.com/s/files/1/0429/6222/3263/files/french_partitive_articles_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0497/5404/6618/files/16942586421.pdf
- https://cdn.shopify.com/s/files/1/0501/0771/1653/files/89979638270.pdf
- https://cdn.shopify.com/s/files/1/0482/9383/9009/files/votodizapodufikof.pdf
- https://site-1044498.mozfiles.com/files/1044498/link_para_baixar_fortnite_no_android.pdf
- https://site-1040601.mozfiles.com/files/1040601/jowinuxopidavipitogo.pdf
- https://site-1043434.mozfiles.com/files/1043434/vulusapusivisifu.pdf
- https://site-1039355.mozfiles.com/files/1039355/83198448897.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1042677.mozfiles.com
- site-1042345.mozfiles.com
- site-1044300.mozfiles.com
- site-1048221.mozfiles.com
- cdn.shopify.com
- site-1044498.mozfiles.com
- site-1040601.mozfiles.com
- site-1043434.mozfiles.com
- site-1039355.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report