SUSPICIOUS — 342536051de708.pdf
SUSPICIOUS — 342536051de708.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
dbe236784d02d86501fc277c3db3d186e45b434113e6cda6da6a5703cfde320f - SHA-1:
56006057d363085561ad39d1192d63496c7102c6 - MD5:
fb2da7c45bd6d30d25aba3f007348a98 - ssdeep:
768:TgGzpDUeJrUObHHVbfD1Bs4PCizRFaw/qOfJf+MVsF+wJbFO7qT88QIF:sGFYe9UGNb/qOwps4E8QIF - TLSH:
T16E338DF310A7DE8C7AC7DB43A9EA246D5149D7485073A6A19588773DC47C3BEBE40A00 - Submitted as: 342536051de708.pdf
- File type: pdf · Size: 49380 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=i%20751%20cover%20letter%20example, https://uploads.strikinglycdn.com/files/ff47ff24-3019-42fa-90c7-6402d038d2c7/60034511363.pdf, https://uploads.strikinglycdn.com/files/ef75332a-1ca9-420b-a72f-9612ba726e9b/48129139468.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=i%20751%20cover%20letter%20example
- https://uploads.strikinglycdn.com/files/ff47ff24-3019-42fa-90c7-6402d038d2c7/60034511363.pdf
- https://uploads.strikinglycdn.com/files/ef75332a-1ca9-420b-a72f-9612ba726e9b/48129139468.pdf
- https://uploads.strikinglycdn.com/files/e68e509a-0771-4103-80c9-7af849bb60c7/54298661130.pdf
- https://site-1048453.mozfiles.com/files/1048453/69691144820.pdf
- https://site-1039174.mozfiles.com/files/1039174/taxofunasivimu.pdf
- https://cdn.shopify.com/s/files/1/0435/4539/5368/files/best_ps3_controller_driver_for_windows_10.pdf
- https://cdn.shopify.com/s/files/1/0484/7897/8210/files/84030776545.pdf
- https://cdn.shopify.com/s/files/1/0437/3338/5381/files/44238185390.pdf
- https://cdn.shopify.com/s/files/1/0433/7241/3079/files/lusumokamik.pdf
- https://cdn.shopify.com/s/files/1/0497/8026/1025/files/computers_inside_and_outer_hardware_labeling_worksheet_answers.pdf
- https://uploads.strikinglycdn.com/files/ae58ceb7-48d6-4242-beaa-c632f6a144a2/wufenajitafifubodogaxabir.pdf
- https://uploads.strikinglycdn.com/files/86eb2f45-a10f-435c-8903-df4c471b8618/47450472742.pdf
- https://uploads.strikinglycdn.com/files/88d599b5-b1cc-4ee1-86f4-4f741b54b63b/70147238289.pdf
- https://uploads.strikinglycdn.com/files/20a2de18-73a6-42f3-899e-c4789d03be46/20410805137.pdf
- https://uploads.strikinglycdn.com/files/5a88e77f-841f-4a05-aa7b-0e37305f34d9/lagerijaxoloxovefu.pdf
- https://uploads.strikinglycdn.com/files/383befa4-1dfe-4992-957e-bc57a89ac6a4/liruvavix.pdf
- https://uploads.strikinglycdn.com/files/1a82c53a-db9e-469f-bbef-625f3129b043/wijakovajamubinazevofomo.pdf
- https://site-1038880.mozfiles.com/files/1038880/45696697641.pdf
- https://site-1043081.mozfiles.com/files/1043081/19078730058.pdf
- https://site-1042765.mozfiles.com/files/1042765/89885005145.pdf
- https://site-1039446.mozfiles.com/files/1039446/gotimevimotom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1048453.mozfiles.com
- site-1039174.mozfiles.com
- cdn.shopify.com
- site-1038880.mozfiles.com
- site-1043081.mozfiles.com
- site-1042765.mozfiles.com
- site-1039446.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report