SUSPICIOUS — 7930590.pdf
SUSPICIOUS — 7930590.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
ccdd93255943d045a8751b4ffbdaeee2fe1493fa97d3d5101fb85825c63d1729 - SHA-1:
c06ea97802b22f58169fb7db13fdc3e88016a4ad - MD5:
bb161f18fd749d94fdfbca5948c50445 - ssdeep:
768:+gGzpDppIcGQOfJgPu8mgweSBi52UWU3ZT2Rpgbq0P8UGatZR:7GFVpjmgDSByWU3ZbbXkUGoZR - TLSH:
T16332AEF390E3ED8CBA8B5703AEAA15955589D78CA03697A0408C373DC4BC6FD6E10D60 - Submitted as: 7930590.pdf
- File type: pdf · Size: 43679 bytes
- Verdict: suspicious (44/100)
Detections (2 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=speaker%20cabinet%20design%20theory, https://cdn-cms.f-static.net/uploads/4366959/normal_5f877dff5bccf.pdf, https://cdn-cms.f-static.net/uploads/4365659/normal_5f8701041dcff.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=speaker%20cabinet%20design%20theory
- https://cdn-cms.f-static.net/uploads/4366959/normal_5f877dff5bccf.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f8701041dcff.pdf
- https://cdn-cms.f-static.net/uploads/4369645/normal_5f8802bcf1fbe.pdf
- https://cdn-cms.f-static.net/uploads/4368760/normal_5f87a37926de5.pdf
- https://cdn-cms.f-static.net/uploads/4367312/normal_5f887439a83c4.pdf
- https://site-1041208.mozfiles.com/files/1041208/30755340352.pdf
- https://site-1036737.mozfiles.com/files/1036737/29999987443.pdf
- https://site-1038505.mozfiles.com/files/1038505/4823624929.pdf
- https://site-1043220.mozfiles.com/files/1043220/sorutot.pdf
- https://sevanilab.weebly.com/uploads/1/3/1/4/131437268/poxob.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/fubisi.pdf
- https://cdn-cms.f-static.net/uploads/4368251/normal_5f8787fb303a0.pdf
- https://cdn-cms.f-static.net/uploads/4369802/normal_5f884a06e8c96.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nimemoroligamaj-tafixidupara.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/d1db2.pdf
- https://sakuvajavabese.weebly.com/uploads/1/3/1/3/131383602/sepulizebiz.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/8fd1a9303cb.pdf
- https://uploads.strikinglycdn.com/files/703c6e32-22b4-4003-b9ce-5538e3e568c2/44635689169.pdf
- https://uploads.strikinglycdn.com/files/8ece91c3-614a-4897-a851-a8c3efe58561/wigasugujovizafu.pdf
- https://uploads.strikinglycdn.com/files/768302cf-d025-4bc0-91bf-224e7916bbd9/zitokosileluxomala.pdf
- https://uploads.strikinglycdn.com/files/f555bdd4-984d-48b2-a18c-4e062ccd8e47/migesemulotasupavazudada.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1041208.mozfiles.com
- site-1036737.mozfiles.com
- site-1038505.mozfiles.com
- site-1043220.mozfiles.com
- sevanilab.weebly.com
- dutitujazekap.weebly.com
- jakedekokobara.weebly.com
- pumowurunumig.weebly.com
- sakuvajavabese.weebly.com
- taxajadotediru.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report