SUSPICIOUS — 80336660897.pdf
SUSPICIOUS — 80336660897.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d0cff25ad1aac7dff98757cabb630827a7a606f88ff95ffbb6755287b8c9d3f4 - SHA-1:
7a769356f9001a283d0e7a03c962956982d1f27e - MD5:
5cf31e358846a957e934e704e3b0c060 - ssdeep:
3072:jF3Mgj9JXB53Z1l5yOgHfElQJMwCjn+23bz:R8o9ZB5Z1l55gHQ+1Cjh - TLSH:
T1993CE1F35197CD1C7AC7FB036E92149C5189DB49A03296A488DCB9ACC8B877DAF02D05 - Submitted as: 80336660897.pdf
- File type: pdf · Size: 119662 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=boundary+conditions+in+cfd+pdf, http://files.lagunabeachkitehouse.com/uploads/1/3/0/7/130775432/a0be8338a.pdf, http://files.capitalareaanesthesia.com/uploads/1/3/2/7/132710661/komokixuj_defumozepakage.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=boundary+conditions+in+cfd+pdf
- http://files.lagunabeachkitehouse.com/uploads/1/3/0/7/130775432/a0be8338a.pdf
- http://files.capitalareaanesthesia.com/uploads/1/3/2/7/132710661/komokixuj_defumozepakage.pdf
- http://foborov.audleymills.co.uk/uploads/1/3/1/4/131437693/6762825.pdf
- https://uploads.strikinglycdn.com/files/dbabc27c-256c-46f3-9a50-dae504dd9de3/97559642483.pdf
- https://uploads.strikinglycdn.com/files/fc6d66b3-2ca2-4dc5-8267-06a39640c212/pixixiterevegejawubu.pdf
- https://uploads.strikinglycdn.com/files/2231960b-9393-492f-8973-6b147b6eee28/pasiwinaludu.pdf
- https://uploads.strikinglycdn.com/files/31bf37d1-12e0-45d6-8e4a-44574074f480/37825940293.pdf
- https://uploads.strikinglycdn.com/files/c482154c-bd9d-4829-a1a2-39b6cfaf5430/satesizawagefudemaburaten.pdf
- http://dikix.spinninpolestudio.com/uploads/1/3/0/8/130813979/fajor_kajinagobenefa_mibujazimu_pevadeliwosoj.pdf
- http://wunesid.igrivera.com/uploads/1/3/1/1/131164460/nojozu-xilukolegetix-gifokiravuv.pdf
- http://divubiti.thedojoparamus.com/uploads/1/3/1/4/131438234/lomufubakuwiwonaso.pdf
- http://files.samuelosterhout.com/uploads/1/3/1/1/131163660/70d5cea8.pdf
- http://files.okcstairclimb.com/uploads/1/3/1/4/131483153/3718992.pdf
- http://files.madcityparagliding.com/uploads/1/3/1/4/131482892/gidaramokagoti.pdf
- http://vugonol.clemonscustomwoodwork.com/uploads/1/3/0/7/130739651/6c5d6f764.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.lagunabeachkitehouse.com
- files.capitalareaanesthesia.com
- foborov.audleymills.co.uk
- uploads.strikinglycdn.com
- dikix.spinninpolestudio.com
- wunesid.igrivera.com
- divubiti.thedojoparamus.com
- files.samuelosterhout.com
- files.okcstairclimb.com
- files.madcityparagliding.com
- vugonol.clemonscustomwoodwork.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report