SUSPICIOUS — 72145573126.pdf
SUSPICIOUS — 72145573126.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
fd54619219612b7172b46ceb3f33df605cb6543e77345e0d9fe60bfc19d20353 - SHA-1:
c120d20da1ace404016dd2991bc57b0a81128844 - MD5:
ecc19a34288baff9a09d5f686b6cf82d - ssdeep:
768:0gGzpDD8r2SAwOKILmhO+//FIp268m24ndO:BGFvmO+nFIp9HndO - TLSH:
T1722E7CF35157EC8D768BAB03AEE60059618AD74CA02697B0548C7B3CD87C6FD7E10A60 - Submitted as: 72145573126.pdf
- File type: pdf · Size: 32170 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=la+era+de+la+revolucion+eric+hobsbawm+pdf+gratis, https://uploads.strikinglycdn.com/files/e013174f-9ec2-45e6-8fd1-e3fd2131a85d/4336159882.pdf, https://uploads.strikinglycdn.com/files/d7090299-ff7e-4338-831d-6edeecf38a81/78640578506.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=la+era+de+la+revolucion+eric+hobsbawm+pdf+gratis
- https://uploads.strikinglycdn.com/files/e013174f-9ec2-45e6-8fd1-e3fd2131a85d/4336159882.pdf
- https://uploads.strikinglycdn.com/files/d7090299-ff7e-4338-831d-6edeecf38a81/78640578506.pdf
- https://uploads.strikinglycdn.com/files/bfd3f659-6eae-4c68-b478-911017d115f9/83280898917.pdf
- https://uploads.strikinglycdn.com/files/3dd7ecfd-7a6c-4f2a-83af-7fb3188400d9/kobixukizokasezenapoz.pdf
- https://site-1038472.mozfiles.com/files/1038472/12589214641.pdf
- https://site-1036646.mozfiles.com/files/1036646/xoralufawuxigisa.pdf
- https://site-1042624.mozfiles.com/files/1042624/88316655095.pdf
- https://cdn.shopify.com/s/files/1/0437/6838/1591/files/cure_moderate_wounds_potion_pathfinder.pdf
- https://cdn.shopify.com/s/files/1/0428/2882/4742/files/ravewepedaronowavakome.pdf
- https://cdn.shopify.com/s/files/1/0427/9150/1990/files/j_power_source.pdf
- https://cdn.shopify.com/s/files/1/0480/0708/6239/files/vegawen.pdf
- https://cdn.shopify.com/s/files/1/0484/9159/3889/files/vewelevonipisevo.pdf
- https://cdn.shopify.com/s/files/1/0485/8966/8512/files/62592976696.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1038472.mozfiles.com
- site-1036646.mozfiles.com
- site-1042624.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report