SUSPICIOUS — abfa71deb67a.pdf
SUSPICIOUS — abfa71deb67a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f35d3c77e57094008747760a164e4058f90226b2572a814d51b956f57b9b7c39 - SHA-1:
6a6a66a9df983cf39ddce34ac7f097b9d8185e21 - MD5:
bd7fecd01db59239b6bb0ae6bec161c0 - ssdeep:
768:sgGzpDAeEkGOsvfKZXtGw6kixVqip7G7c9WLjGmh8CuFNkoSafWMdbAJw:pGFsekun7+wjGmKCVoAkbAJw - TLSH:
T187338DF310A7ED8D7B879B43A9B7115A518AD38C6132E7904548376CC6BC9BC7F10A60 - Submitted as: abfa71deb67a.pdf
- File type: pdf · Size: 48792 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=wedding%20reception%20decor%20checklist%20pdf, https://cdn.shopify.com/s/files/1/0498/9331/0631/files/xepiruzebulegex.pdf, https://cdn.shopify.com/s/files/1/0497/2891/3560/files/pudusumi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=wedding%20reception%20decor%20checklist%20pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/xepiruzebulegex.pdf
- https://cdn.shopify.com/s/files/1/0497/2891/3560/files/pudusumi.pdf
- https://cdn.shopify.com/s/files/1/0438/0898/1153/files/oracion_de_alabanza_al_espiritu_santo.pdf
- https://cdn.shopify.com/s/files/1/0481/4153/3347/files/7574840919.pdf
- https://cdn.shopify.com/s/files/1/0480/7481/7693/files/98331066643.pdf
- https://s3.amazonaws.com/jotizifime/buerger_s_exercises.pdf
- https://s3.amazonaws.com/bubeto/tiniwasopuk.pdf
- https://s3.amazonaws.com/wunupalezozerud/home_alone_piano.pdf
- https://s3.amazonaws.com/zirojopemup/congenital_heart_disease_download.pdf
- https://s3.amazonaws.com/tujeviwakirawu/data_structures_and_algorithms_with_javascript_o_reilly.pdf
- https://s3.amazonaws.com/wesezuzuvalirik/93326828857.pdf
- https://s3.amazonaws.com/susopuzupure/aadhar_card_form_download_2019.pdf
- https://s3.amazonaws.com/jagux/82482533969.pdf
- https://s3.amazonaws.com/toliwudalamem/pdf_to_dwg_online_without_email.pdf
- https://cdn.shopify.com/s/files/1/0502/9661/9193/files/android_custom_dialog_style_example.pdf
- https://cdn.shopify.com/s/files/1/0497/7888/4759/files/management_and_leadership_theories.pdf
- https://uploads.strikinglycdn.com/files/1d301c40-e380-4ba8-8d16-74534d1c67fd/9621356478.pdf
- https://uploads.strikinglycdn.com/files/3a77c274-ebb1-4830-aea6-63dfa5185095/32469324277.pdf
- https://uploads.strikinglycdn.com/files/23e7e5b8-63dd-4193-a165-88f195aad2b9/ledulunasovarenaxut.pdf
- https://uploads.strikinglycdn.com/files/e4b9c920-e0af-45f2-bead-114aa3982559/creative_sound_blasterx_kratos_s5.pdf
- https://cdn.shopify.com/s/files/1/0481/1879/2345/files/57238276953.pdf
- https://cdn.shopify.com/s/files/1/0504/4204/3561/files/tenses_rules_chart.pdf
- https://cdn.shopify.com/s/files/1/0433/0674/6011/files/25999382246.pdf
- https://cdn.shopify.com/s/files/1/0482/5822/0187/files/list_of_words_that_rhyme_with_guide.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report