SUSPICIOUS — 30215878944.pdf
SUSPICIOUS — 30215878944.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
defd8c1884f662c1a5afa1a4c5213902798d9e0621a7dafe1b005658b134cd29 - SHA-1:
b44b3cd85e48c9968ed631aad76716020ea948da - MD5:
0862686ff65b4d698570c1bdc24a0de6 - ssdeep:
768:XgGzpDAhXVsfBNuhEBcIGmOx8O+p+v3qpPZ0HASa27z2nIjlKD15yHETtp:wGFMkcJxX6kqZ9Sa27SneKD1uETtp - TLSH:
T19532AFF35197FD8C7A8B9B036DEB00586185D68821339A6055887B3CC4BC6BC7E14E70 - Submitted as: 30215878944.pdf
- File type: pdf · Size: 46300 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=resident+evil+3+walkthroughs, https://cdn.shopify.com/s/files/1/0433/7913/0531/files/pellon_fusible_interfacing_for_masks.pdf, https://cdn.shopify.com/s/files/1/0477/5631/2732/files/vulenofegunurirevonitim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=resident+evil+3+walkthroughs
- https://cdn.shopify.com/s/files/1/0433/7913/0531/files/pellon_fusible_interfacing_for_masks.pdf
- https://cdn.shopify.com/s/files/1/0477/5631/2732/files/vulenofegunurirevonitim.pdf
- https://cdn.shopify.com/s/files/1/0479/5711/5036/files/potanigobovosigalogurud.pdf
- https://site-1037850.mozfiles.com/files/1037850/16313936811.pdf
- https://site-1039631.mozfiles.com/files/1039631/83568855919.pdf
- https://site-1036767.mozfiles.com/files/1036767/65031536671.pdf
- https://site-1036944.mozfiles.com/files/1036944/82570495378.pdf
- https://site-1039676.mozfiles.com/files/1039676/pekogo.pdf
- https://uploads.strikinglycdn.com/files/f9a9b8f2-3db1-4d06-b383-807b4fb226c9/zaxuzubafiluxojalawuje.pdf
- https://uploads.strikinglycdn.com/files/150ba16b-4a6f-4f31-849d-053242becb1e/87962363760.pdf
- https://uploads.strikinglycdn.com/files/cc9daea1-8835-4ce6-9a83-c924953be40f/ladubolotozo.pdf
- https://uploads.strikinglycdn.com/files/6c65ed0d-c1bb-43c8-9da9-ec74dbef64dc/zanigexetorusuro.pdf
- https://uploads.strikinglycdn.com/files/ea7861c9-7f6c-49a3-9301-4524ada5eb01/35804975952.pdf
- https://uploads.strikinglycdn.com/files/3a51b5dc-39fb-4d76-b1ce-99762391c4ac/gugogezoma.pdf
- https://uploads.strikinglycdn.com/files/a8a470b4-e1c8-4271-b648-4c7520ddd975/59359569673.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1037850.mozfiles.com
- site-1039631.mozfiles.com
- site-1036767.mozfiles.com
- site-1036944.mozfiles.com
- site-1039676.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report