SUSPICIOUS — 6341600.pdf
SUSPICIOUS — 6341600.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
fad9a82ea94bcb2792b59ea0994aed1840f4c1f997925e0c44643c127221c7fa - SHA-1:
d1108c5b648a11740f853b6005037a06a25a7614 - MD5:
e4e54aa99ff826a2d8314043b85f5e04 - ssdeep:
768:YgGzpDJOpBlnHluMyqf5CdWrTJ/StqppFw+nSKHtRLzUShe+iDiQBUZu:1GFVOpBzCduJ1pu+nDHt9zNhQOQBUZu - TLSH:
T1F4316CF350A7DD4C7A8F6B079DAA1518A08ED78D613397A04488376CC4BC5FE3E10A65 - Submitted as: 6341600.pdf
- File type: pdf · Size: 42280 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=plush%20boyds%20bears%20value%20guide, https://uploads.strikinglycdn.com/files/f4ac5729-418d-4ce9-88b5-83c86d647779/16311848329.pdf, https://uploads.strikinglycdn.com/files/0fa620e5-ef62-420a-a08e-bd7e44e43cd4/63626923097.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=plush%20boyds%20bears%20value%20guide
- https://uploads.strikinglycdn.com/files/f4ac5729-418d-4ce9-88b5-83c86d647779/16311848329.pdf
- https://uploads.strikinglycdn.com/files/0fa620e5-ef62-420a-a08e-bd7e44e43cd4/63626923097.pdf
- https://uploads.strikinglycdn.com/files/1930566c-e843-4fa1-a0a6-ecd1d6547ce1/rurasivuzukadotakili.pdf
- https://uploads.strikinglycdn.com/files/8f8d7f30-f139-496a-82af-bf231769916d/10141326144.pdf
- https://uploads.strikinglycdn.com/files/5c0c64d9-67a6-4588-a9df-99b062c13345/41772652572.pdf
- https://uploads.strikinglycdn.com/files/5c2b3c6b-6ee2-4c67-b4c8-c605a866485d/jebosawigurorubujiw.pdf
- https://uploads.strikinglycdn.com/files/ae468738-5fa9-4deb-8827-c83a525e46d2/24667160603.pdf
- https://uploads.strikinglycdn.com/files/d1115776-e124-49f7-9cc2-14046e433796/netekafipada.pdf
- https://uploads.strikinglycdn.com/files/2c867250-0b21-4b09-9fad-b87b2bd767f1/71282841661.pdf
- https://cdn-cms.f-static.net/uploads/4366973/normal_5f873626c77fd.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f86fecf0076f.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f516230e2.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f872f0cabdd1.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f86f6e213569.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f8722de5af8b.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f87144de6036.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f872280bfa1e.pdf
- https://site-1037230.mozfiles.com/files/1037230/41197873686.pdf
- https://site-1042917.mozfiles.com/files/1042917/xakif.pdf
- https://site-1041613.mozfiles.com/files/1041613/96041989217.pdf
- https://site-1040427.mozfiles.com/files/1040427/sawatejeros.pdf
- https://site-1043607.mozfiles.com/files/1043607/nedevaxa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1037230.mozfiles.com
- site-1042917.mozfiles.com
- site-1041613.mozfiles.com
- site-1040427.mozfiles.com
- site-1043607.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report