SUSPICIOUS — 9595517.pdf
SUSPICIOUS — 9595517.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ec48e3b9cc0772972228abac379af140e1bd847d9faed5e80a595cc539e1b6d3 - SHA-1:
861e2a556abd1fad5c368a5733cf40895ae6d9d3 - MD5:
b7bacf82d6dfd3dd0419af5157cf72d0 - ssdeep:
768:mgGzpDQpRx7qI+f6qnIi4EaafBD4viaZ4lcxQvupBVvJq9vdCAMe1N:zGFMp85Dfa85vuFvJqd89e1N - TLSH:
T18E329EF74487ED4CBF8AAB43ACE70169149AD6896132E35044CC772DD4BC6AD7E10921 - Submitted as: 9595517.pdf
- File type: pdf · Size: 45535 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=jeep%20patriot%20manual%20transmission%20replacement%20cost, https://cdn.shopify.com/s/files/1/0483/2313/3604/files/34705052778.pdf, https://cdn.shopify.com/s/files/1/0486/2581/1624/files/61941769395.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=jeep%20patriot%20manual%20transmission%20replacement%20cost
- https://cdn.shopify.com/s/files/1/0483/2313/3604/files/34705052778.pdf
- https://cdn.shopify.com/s/files/1/0486/2581/1624/files/61941769395.pdf
- https://cdn.shopify.com/s/files/1/0497/8868/2401/files/milwaukee_police_scanner_feed.pdf
- https://cdn.shopify.com/s/files/1/0481/8442/6663/files/ariens_deluxe_28_parts_manual.pdf
- https://uploads.strikinglycdn.com/files/ef765dd9-06bd-45f6-8524-e0d9d8eb17f2/sabodi.pdf
- https://uploads.strikinglycdn.com/files/1c8ec5c4-f821-42b9-89b9-a002b6288eb5/29338173461.pdf
- https://uploads.strikinglycdn.com/files/c7388742-f5df-466a-891f-fe60390c26c4/vudigovupobu.pdf
- https://uploads.strikinglycdn.com/files/67639b6d-fe32-44dd-8a28-d29ca6ea10f6/74693627494.pdf
- https://cdn.shopify.com/s/files/1/0502/8446/2274/files/auditor_general_report_2020_ghana.pdf
- https://cdn.shopify.com/s/files/1/0483/3483/1779/files/33.1_the_circulatory_system_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0481/3822/3769/files/voice_changer_plus_apk.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f873fc4a5b8b.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f8729dd62de0.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f8718114419c.pdf
- https://site-1038840.mozfiles.com/files/1038840/rurajixomoteturo.pdf
- https://site-1043453.mozfiles.com/files/1043453/38633095950.pdf
- https://site-1043771.mozfiles.com/files/1043771/54818824730.pdf
- https://site-1048185.mozfiles.com/files/1048185/pikubonevulefuxuja.pdf
- https://site-1037911.mozfiles.com/files/1037911/67082243559.pdf
- https://site-1048559.mozfiles.com/files/1048559/49284702845.pdf
- https://site-1039837.mozfiles.com/files/1039837/nuloremirifiwabul.pdf
- https://site-1044151.mozfiles.com/files/1044151/85085678171.pdf
- https://site-1038422.mozfiles.com/files/1038422/42546007074.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1038840.mozfiles.com
- site-1043453.mozfiles.com
- site-1043771.mozfiles.com
- site-1048185.mozfiles.com
- site-1037911.mozfiles.com
- site-1048559.mozfiles.com
- site-1039837.mozfiles.com
- site-1044151.mozfiles.com
- site-1038422.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report