SUSPICIOUS — 3437590.pdf
SUSPICIOUS — 3437590.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d59981afa985b4b11ff201f9ff861c146248e91ba324157e895846217dd9149f - SHA-1:
5f638bbc85ad2bb9c6104d7deaad96f0bd2b4bd9 - MD5:
f967bf8975980e896bc4ff87cfe26477 - ssdeep:
768:ugGzpDjp+Vfz5h/Gf7GFYyEosvLUriKkidQOm4a9nLbCbplY52LfYKfccvWAOGxx:LGFHplvwrXuNbQm5EfYAd2Yl6eqptJ4 - TLSH:
T16B349CF31097DC8DBA47EB436CAB1158219AD389B227A7704888763CC4BC6BD7F50921 - Submitted as: 3437590.pdf
- File type: pdf · Size: 53802 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=the%20bourne%20identity%201080p, https://site-1040326.mozfiles.com/files/1040326/lusamajutipolukuzaza.pdf, https://site-1040359.mozfiles.com/files/1040359/95627655720.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=the%20bourne%20identity%201080p
- https://site-1040326.mozfiles.com/files/1040326/lusamajutipolukuzaza.pdf
- https://site-1040359.mozfiles.com/files/1040359/95627655720.pdf
- https://site-1042781.mozfiles.com/files/1042781/lopaziwukozuruxexuwosi.pdf
- https://site-1044245.mozfiles.com/files/1044245/mosekoviwafijenivuxe.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f8815cab30a7.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f880e2231e47.pdf
- https://cdn-cms.f-static.net/uploads/4369922/normal_5f880ea95b426.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f87141ab2611.pdf
- https://site-1041198.mozfiles.com/files/1041198/kefojofo.pdf
- https://site-1040432.mozfiles.com/files/1040432/milewinojevanolujusunu.pdf
- https://cdn.shopify.com/s/files/1/0498/7686/1086/files/dadegunizazopi.pdf
- https://cdn.shopify.com/s/files/1/0266/9720/3886/files/sams_club_gazebo_with_netting.pdf
- https://cdn.shopify.com/s/files/1/0432/3626/2050/files/lubaliluleriboduxita.pdf
- https://cdn.shopify.com/s/files/1/0482/3023/6314/files/kubazekomife.pdf
- https://cdn.shopify.com/s/files/1/0427/7728/0671/files/did_you_get_it_practica_de_gramatica_answer_key_level_1.pdf
- https://cdn.shopify.com/s/files/1/0433/6877/5841/files/66551709757.pdf
- https://cdn.shopify.com/s/files/1/0482/7470/2500/files/manual_fiat_palio_fire_2020.pdf
- https://cdn.shopify.com/s/files/1/0431/6721/9878/files/synthesis_of_alum_lab_answers.pdf
- https://uploads.strikinglycdn.com/files/9fea3ec1-7db8-445c-b24d-99bbb78af187/60908709428.pdf
- https://uploads.strikinglycdn.com/files/e7934ae0-1b42-4327-b11f-6456ceabbdd6/ruwenakajotat.pdf
- https://uploads.strikinglycdn.com/files/c5e6731a-7338-4234-8a7e-20ca62449b6e/tawupazedufakad.pdf
- https://uploads.strikinglycdn.com/files/a60fbb83-73bd-48e1-9715-b5c0f647f746/50806288094.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- site-1040326.mozfiles.com
- site-1040359.mozfiles.com
- site-1042781.mozfiles.com
- site-1044245.mozfiles.com
- cdn-cms.f-static.net
- site-1041198.mozfiles.com
- site-1040432.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report