SUSPICIOUS — 7fa06aa325.pdf
SUSPICIOUS — 7fa06aa325.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e750814aa9c202d2ff7698ed9f812d347cc56f65911a53572c21a9b4ce8dccba - SHA-1:
88aa3f6b552c20924e2d35fdc5d0b29e1b1631ce - MD5:
645b661ebb0e8fe8bde99c36460cf871 - ssdeep:
768:ngGzpDEpG2wlJ4SsIJ3Yk/tnsNLjnZwYNy2wg3iy7lbJvqTtd+i0/8J5rY3qhXNW:gGFwpG2knLNdFnsXwelpi0EJ5U3+NiAW - TLSH:
T16E329FF354ABED0C3E4A9B079DA611AA5149DB4C21329360488C7B3CC1BC6FE6E44B65 - Submitted as: 7fa06aa325.pdf
- File type: pdf · Size: 47049 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=free%20wedding%20invitations%20templates%20t, https://cdn.shopify.com/s/files/1/0435/3117/4043/files/daddy_by_sylvia_plath_shmoop.pdf, https://cdn.shopify.com/s/files/1/0498/8734/6846/files/the_fresh_air_fund_new_york.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=free%20wedding%20invitations%20templates%20t
- https://cdn.shopify.com/s/files/1/0435/3117/4043/files/daddy_by_sylvia_plath_shmoop.pdf
- https://cdn.shopify.com/s/files/1/0498/8734/6846/files/the_fresh_air_fund_new_york.pdf
- https://cdn.shopify.com/s/files/1/0483/6343/8243/files/download_game_biohazard_5_apk.pdf
- https://wedebiki.weebly.com/uploads/1/3/0/9/130969436/62adad3655c9b5.pdf
- https://cdn.shopify.com/s/files/1/0434/9257/3336/files/five_languages_of_love_for_singles.pdf
- https://cdn.shopify.com/s/files/1/0434/2385/8845/files/bamilami.pdf
- https://cdn.shopify.com/s/files/1/0440/7332/0600/files/furedoxigedi.pdf
- https://cdn.shopify.com/s/files/1/0430/8339/9329/files/mike_barnes_cobra_kai_actor.pdf
- https://uploads.strikinglycdn.com/files/94ffe5d6-fc22-4adc-adce-1952127f9324/22740568503.pdf
- https://uploads.strikinglycdn.com/files/d4c5bbae-52a9-4d3a-9594-eb4a4558d179/38363115590.pdf
- https://uploads.strikinglycdn.com/files/aad40d28-1589-4ce4-b17d-862a246238a9/90855842961.pdf
- https://uploads.strikinglycdn.com/files/0a3e6059-6d55-4dbc-be9d-e87b1dc88388/52115545124.pdf
- https://uploads.strikinglycdn.com/files/9246a7d2-543c-4b51-887b-8223dc69eb80/53215927655.pdf
- https://uploads.strikinglycdn.com/files/58f0e578-7dda-46d6-92e2-8f773c6dafe3/kekimubuxafitone.pdf
- https://uploads.strikinglycdn.com/files/91ccb2db-51a0-49ff-8dc1-02012eba4445/japalavamufo.pdf
- https://uploads.strikinglycdn.com/files/7acbb328-3e0f-4047-af57-84e7b8b13f13/94651104696.pdf
- https://uploads.strikinglycdn.com/files/9d746f3a-efbe-402c-95ee-19585d4aa88d/simevizupofisulaguxufipe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- wedebiki.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report