SUSPICIOUS — 79049104542.pdf
SUSPICIOUS — 79049104542.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e8605312d3995f50e986319e520154e9bb46fcb38083d1b493c1a56b0a8f6f9a - SHA-1:
b890b889b9eb7695cb09ad24bb1c8f09fd07b3f0 - MD5:
39cb2432bb0b99465b97000b0b5f5898 - ssdeep:
1536:jGFma5EWizdmV+GKdbE2tUJmcpmgugHjMtMJvNfgUxHPpe:yFma5di0V+GK5vtUQguyjAMJlf7xHk - TLSH:
T13D38D0F35063ED4DA99BAF87ECBA26456069C24A3176A35054CC6B3CD8BC6BD3F40250 - Submitted as: 79049104542.pdf
- File type: pdf · Size: 79203 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=temario+oposiciones+administrativo+del+estado+pdf, https://site-1037268.mozfiles.com/files/1037268/todukolewosasodufiz.pdf, https://site-1036955.mozfiles.com/files/1036955/23370386816.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=temario+oposiciones+administrativo+del+estado+pdf
- https://site-1037268.mozfiles.com/files/1037268/todukolewosasodufiz.pdf
- https://site-1036955.mozfiles.com/files/1036955/23370386816.pdf
- https://site-1037005.mozfiles.com/files/1037005/bisekaxosokugorufed.pdf
- https://site-1037180.mozfiles.com/files/1037180/49811293037.pdf
- https://site-1037166.mozfiles.com/files/1037166/kuranovorow.pdf
- https://site-1037122.mozfiles.com/files/1037122/78752482168.pdf
- https://site-1036814.mozfiles.com/files/1036814/xisigot.pdf
- https://site-1037899.mozfiles.com/files/1037899/28190677001.pdf
- https://site-1036685.mozfiles.com/files/1036685/71115374232.pdf
- https://uploads.strikinglycdn.com/files/e8173ac0-ec55-4474-a246-2af95b7ed8b1/75291545280.pdf
- https://uploads.strikinglycdn.com/files/a9ffb37e-26ef-429d-a59d-0942047f47ec/gutifosofire.pdf
- https://uploads.strikinglycdn.com/files/18c5b9aa-8995-4689-9db0-a5f7262061dd/57088110724.pdf
- https://uploads.strikinglycdn.com/files/d8c31084-1a1c-4b1c-9ea6-0d1835ec5c7b/22654963999.pdf
- https://uploads.strikinglycdn.com/files/f4c691e8-de63-4a9f-b2a7-b927b15fb236/budakatitizowusunev.pdf
- https://site-1037843.mozfiles.com/files/1037843/jozifatamidususa.pdf
- https://site-1036760.mozfiles.com/files/1036760/3026860227.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037268.mozfiles.com
- site-1036955.mozfiles.com
- site-1037005.mozfiles.com
- site-1037180.mozfiles.com
- site-1037166.mozfiles.com
- site-1037122.mozfiles.com
- site-1036814.mozfiles.com
- site-1037899.mozfiles.com
- site-1036685.mozfiles.com
- uploads.strikinglycdn.com
- site-1037843.mozfiles.com
- site-1036760.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report