SUSPICIOUS — 685992a87e3194.pdf
SUSPICIOUS — 685992a87e3194.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d39f2ec13a0f3470e611a85444d305a99ed24be59501eb7dcaa2aef426beb78c - SHA-1:
23424a4d410d0c001566ecedc9dc4dead5011440 - MD5:
c9fd88fd8a436b643990ffc7243655c2 - ssdeep:
768:GgGzpDUpm7qXC25iZjNPhLxiiOBRc0Drbe3d/Lw/Fve2HCa:TGFIp6PmzRc0Py3d/8/Be2HCa - TLSH:
T14F318EF340A7ED8C7A8BAF03ADEB15995546D38C6133D790058C3B6DD4BC9AD2E00A61 - Submitted as: 685992a87e3194.pdf
- File type: pdf · Size: 42532 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=doomsday%20last%20shelter, https://uploads.strikinglycdn.com/files/4cdf4cd4-8e96-4792-8fd0-5c4a30337bbe/34370945198.pdf, https://uploads.strikinglycdn.com/files/e1b7dfa2-f84e-424e-8997-bba9da6f02c4/dimiponi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=doomsday%20last%20shelter
- https://uploads.strikinglycdn.com/files/4cdf4cd4-8e96-4792-8fd0-5c4a30337bbe/34370945198.pdf
- https://uploads.strikinglycdn.com/files/e1b7dfa2-f84e-424e-8997-bba9da6f02c4/dimiponi.pdf
- https://uploads.strikinglycdn.com/files/ff9d1a4b-9ada-483b-adcc-0c946dde0b9d/rawogitawe.pdf
- https://uploads.strikinglycdn.com/files/97655667-4397-4bcb-83ba-4038ab6c1547/44089399136.pdf
- https://site-1043613.mozfiles.com/files/1043613/lenixubijet.pdf
- https://site-1043199.mozfiles.com/files/1043199/luroxekajido.pdf
- https://uploads.strikinglycdn.com/files/615dc2f4-87e2-4cda-948e-e5a9eabb85f3/megewesevapedumomegomopu.pdf
- https://uploads.strikinglycdn.com/files/bba8874b-4fc0-453b-92fc-df558b327d49/bulinisigok.pdf
- https://cdn.shopify.com/s/files/1/0430/9581/8397/files/jacobs_ladder_imdb_parents_guide.pdf
- https://cdn.shopify.com/s/files/1/0496/0711/4916/files/dorilijuz.pdf
- https://cdn.shopify.com/s/files/1/0480/4067/3444/files/miraculous_crush_apk_mod.pdf
- https://cdn.shopify.com/s/files/1/0485/3632/2203/files/95678953436.pdf
- https://cdn.shopify.com/s/files/1/0485/0899/3691/files/26387878186.pdf
- https://uploads.strikinglycdn.com/files/3ef84d0b-3244-465a-b6af-1392cfe6cd33/jaziwebekidilasufokawib.pdf
- https://uploads.strikinglycdn.com/files/107e5eff-2539-4f51-ab47-5b3568444895/29162471562.pdf
- https://uploads.strikinglycdn.com/files/eb76f826-7526-4d61-9d11-d76987ba59e0/todisaj.pdf
- https://uploads.strikinglycdn.com/files/fe58389a-52eb-456f-a363-8e0a562007f0/tepel.pdf
- https://uploads.strikinglycdn.com/files/c53ba1a2-cd3c-40bc-93da-c6cdfc5677bf/27582189218.pdf
- https://site-1037920.mozfiles.com/files/1037920/94049838233.pdf
- https://site-1036886.mozfiles.com/files/1036886/92204454115.pdf
- https://site-1042495.mozfiles.com/files/1042495/side_splitter_theorem_practice_worksheet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1043613.mozfiles.com
- site-1043199.mozfiles.com
- cdn.shopify.com
- site-1037920.mozfiles.com
- site-1036886.mozfiles.com
- site-1042495.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report