SUSPICIOUS — 7114067.pdf
SUSPICIOUS — 7114067.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f40fe78cce81e5dcd839ab19c46a8e89c58adcd5967f8630d2066a53323689b1 - SHA-1:
7d7495e262ca4da192d3f520a0218debcf488113 - MD5:
1724fbb4a52dbd7e22763bd88535b44c - ssdeep:
1536:FGFIptRkf6/1o4zLNS3rNjaJ/7gpj2Ntsc1i2r9veO87PySYcB7idtA6:YFIpfkf6D/NSbNWp7glQsmxmX/lidT - TLSH:
T10139E0F365A3DC4D7A8A0B13ADA62265A04DD34961379B90488C373DF4BC6BE7F21412 - Submitted as: 7114067.pdf
- File type: pdf · Size: 88768 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=last%2029%20com, https://uploads.strikinglycdn.com/files/c785b2bb-7d7f-4ea8-a00b-137dc68d2f6c/75812459304.pdf, https://uploads.strikinglycdn.com/files/3e562a8f-e837-4a1a-a1bf-38c2348c025e/xuxolasubuk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=last%2029%20com
- https://uploads.strikinglycdn.com/files/c785b2bb-7d7f-4ea8-a00b-137dc68d2f6c/75812459304.pdf
- https://uploads.strikinglycdn.com/files/3e562a8f-e837-4a1a-a1bf-38c2348c025e/xuxolasubuk.pdf
- https://uploads.strikinglycdn.com/files/f9fa6c88-546b-4c30-9ad1-f0c33db9cd3f/71593681657.pdf
- https://uploads.strikinglycdn.com/files/e5266397-2e16-45be-8abe-ca61ee686b83/83394887421.pdf
- https://uploads.strikinglycdn.com/files/242b18a7-ffe4-4bbc-a96f-35a892626031/43174544921.pdf
- https://uploads.strikinglycdn.com/files/19bafa03-8bf7-45cb-8789-438ba4c9ba89/86541143001.pdf
- https://uploads.strikinglycdn.com/files/dcd2259c-e873-4ef2-9b85-a3910832d91a/84327322460.pdf
- https://uploads.strikinglycdn.com/files/9d9ee4d6-4215-43ae-af09-0d8d3f87704d/mopolunikaligis.pdf
- https://uploads.strikinglycdn.com/files/bd2857d9-28ef-4487-9f27-0bae196eb7b4/jizugowululab.pdf
- https://uploads.strikinglycdn.com/files/71b5c698-27ab-4572-9503-8f44f934cb72/51346807146.pdf
- https://site-1036651.mozfiles.com/files/1036651/jafabotixetumegi.pdf
- https://site-1044204.mozfiles.com/files/1044204/sunalamusux.pdf
- https://site-1040056.mozfiles.com/files/1040056/jovamevujudirazovini.pdf
- https://site-1036753.mozfiles.com/files/1036753/28559183568.pdf
- https://site-1042432.mozfiles.com/files/1042432/17324725298.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f87bc5319e45.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f87ce13e9256.pdf
- https://cdn-cms.f-static.net/uploads/4368732/normal_5f87804aa909e.pdf
- https://uploads.strikinglycdn.com/files/e23c844d-9e30-4989-8e04-e49de0a262df/64304121662.pdf
- https://uploads.strikinglycdn.com/files/6dd50820-565b-4b6a-abea-b1442521ff06/36427547128.pdf
- https://uploads.strikinglycdn.com/files/e3bae918-d8d6-4ad9-9144-a7da47be1a6e/gisojukig.pdf
- https://uploads.strikinglycdn.com/files/47fef463-b676-4617-852c-ecaa8e5b7290/4491951367.pdf
- https://uploads.strikinglycdn.com/files/71be5609-c151-4b3a-8751-d4ab74793552/wowogakemaputotu.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f875be89e6fa.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1036651.mozfiles.com
- site-1044204.mozfiles.com
- site-1040056.mozfiles.com
- site-1036753.mozfiles.com
- site-1042432.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report