SUSPICIOUS — 4390789.pdf
SUSPICIOUS — 4390789.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
d374cc8d7b858621f82bd9cef6bcbb5c28dbdeb9278140b2cfcaaca7d3ff9027 - SHA-1:
b888d88f462281f4e2846ee8bab570576886db01 - MD5:
2a3430314b31f7eb2111770aeb2afdd1 - ssdeep:
768:ZgGzpDVphpt7qbmJoIuuTHDoIl63kNPYP3bVTgcvMY:aGF5phgIlmkCPrVTgcvMY - TLSH:
T16D306BF310B7ED4C7A8BAB875EB71199658AC388612697900488362CD47CAFD7F10961 - Submitted as: 4390789.pdf
- File type: pdf · Size: 38592 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=y%C4%B1ld%C4%B1z%20tilbe%20olsun%20mu%20olmas%C4%B1n%20indir, https://uploads.strikinglycdn.com/files/14eae93c-f858-469d-9504-28b2afda7184/59732956311.pdf, https://uploads.strikinglycdn.com/files/a49093db-9def-4299-82b4-278a321c53f9/pijumomekowulewuroxo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=y%C4%B1ld%C4%B1z%20tilbe%20olsun%20mu%20olmas%C4%B1n%20indir
- https://uploads.strikinglycdn.com/files/14eae93c-f858-469d-9504-28b2afda7184/59732956311.pdf
- https://uploads.strikinglycdn.com/files/a49093db-9def-4299-82b4-278a321c53f9/pijumomekowulewuroxo.pdf
- https://uploads.strikinglycdn.com/files/b13d616c-26f7-4442-8d81-b21630d8f037/98673197804.pdf
- https://uploads.strikinglycdn.com/files/978890bb-8d80-455f-a625-2cf57991134e/89732082473.pdf
- https://uploads.strikinglycdn.com/files/25ec2622-ed13-43be-b0c5-91256243a952/70347038717.pdf
- https://uploads.strikinglycdn.com/files/e3ab2486-39e0-40f6-912a-83d0e7c47027/46599665702.pdf
- https://cdn-cms.f-static.net/uploads/4369310/normal_5f886b4f25f25.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f872dded869f.pdf
- https://cdn-cms.f-static.net/uploads/4367959/normal_5f881d7a82df8.pdf
- https://cdn-cms.f-static.net/uploads/4369150/normal_5f887c6fd01fc.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f875ec67c72b.pdf
- https://rabexowubomisuw.weebly.com/uploads/1/3/1/4/131407155/neserisibudopazas.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/5470614.pdf
- https://gidixelasulam.weebly.com/uploads/1/3/0/7/130739099/0d5d637.pdf
- https://cdn.shopify.com/s/files/1/0481/5867/1015/files/disijibewanenozasabolig.pdf
- https://cdn.shopify.com/s/files/1/0465/2302/3518/files/93970773200.pdf
- https://cdn.shopify.com/s/files/1/0428/2908/6887/files/hockey_meme_gif.pdf
- https://cdn.shopify.com/s/files/1/0484/9120/0674/files/resusilegatexeze.pdf
- https://cdn.shopify.com/s/files/1/0437/0271/4536/files/rwby_white_rose_fanart.pdf
- https://site-1038548.mozfiles.com/files/1038548/ruxirenopuwogokelutobiduz.pdf
- https://site-1041688.mozfiles.com/files/1041688/dibasexanavorijiwogeroja.pdf
- https://site-1038825.mozfiles.com/files/1038825/gepanagujibugufegabuvoze.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- rabexowubomisuw.weebly.com
- xojisige.weebly.com
- gidixelasulam.weebly.com
- cdn.shopify.com
- site-1038548.mozfiles.com
- site-1041688.mozfiles.com
- site-1038825.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report