SUSPICIOUS — 7518724.pdf
SUSPICIOUS — 7518724.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f599ae2c6d5826b70917f58d64ec39ae6b8e6f7256d763100a35d7209c4c085f - SHA-1:
eabe1af7141c614f4005de871fef5774fb4453e2 - MD5:
81c84efe0f1006b1cd55d31c08946cea - ssdeep:
768:NgGzpDmpjAUQS/PHws8IxKHQcAL0eSM1e5n9VnII5UBvDCOb82lvQNuug+12QHeO:uGFSpjlI9VnIBBvGOb8Kvxug+12QHeB0 - TLSH:
T15A317BF310A3ED4C398BAF57ADEB256DA08DCA489133A750609C672CC47C7ADAF10951 - Submitted as: 7518724.pdf
- File type: pdf · Size: 42866 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=connectwise%20university%20report%20writer, https://uploads.strikinglycdn.com/files/b3c05566-3f9c-48e0-bb46-68835ce80e93/55504455433.pdf, https://uploads.strikinglycdn.com/files/96d3ce26-bbd7-4f83-aea1-19e390b7e0b0/lozuweronemi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=connectwise%20university%20report%20writer
- https://uploads.strikinglycdn.com/files/b3c05566-3f9c-48e0-bb46-68835ce80e93/55504455433.pdf
- https://uploads.strikinglycdn.com/files/96d3ce26-bbd7-4f83-aea1-19e390b7e0b0/lozuweronemi.pdf
- https://uploads.strikinglycdn.com/files/45f22f81-28ce-469c-bbb9-06e5d4993364/89600513622.pdf
- https://uploads.strikinglycdn.com/files/72a0961a-d508-4a18-93a4-9e15ac9b856b/16850103949.pdf
- https://cdn-cms.f-static.net/uploads/4371505/normal_5f8a3dda18485.pdf
- https://cdn-cms.f-static.net/uploads/4368471/normal_5f87764676200.pdf
- https://cdn.shopify.com/s/files/1/0501/6931/5488/files/tm_tus_sorular_2020.pdf
- https://cdn.shopify.com/s/files/1/0500/0724/4955/files/gupemoka.pdf
- https://cdn.shopify.com/s/files/1/0495/6500/8028/files/68080570080.pdf
- https://cdn.shopify.com/s/files/1/0432/4936/9252/files/mimafewoboromivusi.pdf
- https://cdn.shopify.com/s/files/1/0439/4916/2654/files/boxojokemopij.pdf
- https://cdn-cms.f-static.net/uploads/4366973/normal_5f88700ec3aa4.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f8b7840510a5.pdf
- https://cdn-cms.f-static.net/uploads/4369660/normal_5f8b6ead56632.pdf
- https://cdn-cms.f-static.net/uploads/4370076/normal_5f8ba8e0a691c.pdf
- https://uploads.strikinglycdn.com/files/a69770ac-71a0-418f-ad4b-d1e5cbf45103/nejebuxudigad.pdf
- https://uploads.strikinglycdn.com/files/9122f489-2e7d-4e4e-a56d-69f0612885ae/54663605856.pdf
- https://cdn-cms.f-static.net/uploads/4381090/normal_5f8b73b71afdc.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f8ba3aea43bf.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f874e04bc597.pdf
- https://cdn-cms.f-static.net/uploads/4373768/normal_5f8b025ae959d.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f86fa6b4b0bf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- 236.hk
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report