SUSPICIOUS — 2332972.pdf
SUSPICIOUS — 2332972.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d9fbce50fbcd6656e887f82a84f79a206a3d9c0c0e255a9eeeda8ca7ad1337d3 - SHA-1:
a4229ea6e3c893798eb8658e998442f0cae312b0 - MD5:
d45a2b6f1070b3e1962e37b25f3ec427 - ssdeep:
3072:nFgpR+aT4eLOyTOQT3NM6QCKlbNWNeMQmJ0Ynbwd:FyRnMeKGJM6QCK3OeLQO - TLSH:
T1FA3CE1E75267EC4C7AC58F63AC9B0176219CD3CC217AAB90458C672DC46C3BE6A51C21 - Submitted as: 2332972.pdf
- File type: pdf · Size: 112633 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=aurora%20afx%20race%20set, https://uploads.strikinglycdn.com/files/215feba7-5a89-4898-8252-347cea541d90/tamopawutapikumabijev.pdf, https://uploads.strikinglycdn.com/files/ff684e52-e94e-4418-9b1a-762957b896f0/29681414518.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=aurora%20afx%20race%20set
- https://uploads.strikinglycdn.com/files/215feba7-5a89-4898-8252-347cea541d90/tamopawutapikumabijev.pdf
- https://uploads.strikinglycdn.com/files/ff684e52-e94e-4418-9b1a-762957b896f0/29681414518.pdf
- https://uploads.strikinglycdn.com/files/162a9574-5fad-4d48-bb38-37cebcc140a5/jovegodogeki.pdf
- https://uploads.strikinglycdn.com/files/a6445225-abec-40a2-89ea-79ffa7d6a4b5/vorujigesawifatas.pdf
- https://uploads.strikinglycdn.com/files/339947b0-1783-463a-bdee-ed420acddafa/76105329224.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f88bc99f2226.pdf
- https://cdn-cms.f-static.net/uploads/4367277/normal_5f87385a09041.pdf
- https://cdn-cms.f-static.net/uploads/4369922/normal_5f88bcd724bf5.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f8710cd257e9.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f88bd9089f2a.pdf
- https://site-1041927.mozfiles.com/files/1041927/tojilemofu.pdf
- https://site-1042622.mozfiles.com/files/1042622/12318342203.pdf
- https://site-1036945.mozfiles.com/files/1036945/zipikukewiweputiwifidaraj.pdf
- https://site-1039476.mozfiles.com/files/1039476/fasazidid.pdf
- https://site-1043890.mozfiles.com/files/1043890/pavariwonul.pdf
- https://wopeduvolevim.weebly.com/uploads/1/3/0/7/130776212/5051530.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/9639254.pdf
- https://fobewesepujub.weebly.com/uploads/1/3/2/3/132303403/podewafi_lamatuvowud_botemuzoxojabof_firamixivosib.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/decd27.pdf
- https://kusanogiwaxug.weebly.com/uploads/1/3/0/8/130873987/d81b7.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/jinitorip-bolag.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/1d1f8ecc085ca.pdf
- https://cdn.shopify.com/s/files/1/0481/4756/2645/files/fusanawuwo.pdf
- https://cdn.shopify.com/s/files/1/0480/5269/9300/files/fundamentals_of_algorithms_mcqs.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1041927.mozfiles.com
- site-1042622.mozfiles.com
- site-1036945.mozfiles.com
- site-1039476.mozfiles.com
- site-1043890.mozfiles.com
- wopeduvolevim.weebly.com
- tavumake.weebly.com
- fobewesepujub.weebly.com
- zesopupejilit.weebly.com
- kusanogiwaxug.weebly.com
- gimejexoxixaza.weebly.com
- mogilifus.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report