SUSPICIOUS — 2212716.pdf
SUSPICIOUS — 2212716.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
012521a0ef0911f8dada14fb155e35f1bc9abe3a2c15f1e0a4383cb772980b2a - SHA-1:
16afeb162a5149cec327ca6d0cd41b1b266a2538 - MD5:
aecc1905bdbcf0600296339852e98ff7 - ssdeep:
768:qgGzpDiexg0GG7RRV4UI8GpE476OTQ8kxzSXmbTnTiJyGqhy:3GFmeC1AVsv76iINTn+5qhy - TLSH:
T11B337DF310E3ED8CBACFAB03ADAB1559558AC789613696A0048C732CD4BC6FD7E40654 - Submitted as: 2212716.pdf
- File type: pdf · Size: 48932 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=inferno%20august%20strindberg%20pdf, https://fidevawane.weebly.com/uploads/1/3/0/8/130814252/4203336.pdf, https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/wixudufitogipef-fasakimuminob-vofuradadop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=inferno%20august%20strindberg%20pdf
- https://fidevawane.weebly.com/uploads/1/3/0/8/130814252/4203336.pdf
- https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/wixudufitogipef-fasakimuminob-vofuradadop.pdf
- https://xijoxamapapi.weebly.com/uploads/1/3/4/3/134337958/7be7ee6bc0e2e75.pdf
- https://rajomiluti.weebly.com/uploads/1/3/2/6/132682989/42769.pdf
- https://uploads.strikinglycdn.com/files/68bf97f3-b98d-4829-a43c-f86129e09e27/xukig.pdf
- https://uploads.strikinglycdn.com/files/d054b598-1c6c-4bd5-88c7-000d70b108ee/mupidelonejeluvip.pdf
- https://uploads.strikinglycdn.com/files/dc2679a9-6745-4e0b-9927-be6c22a23fdd/26010685718.pdf
- https://uploads.strikinglycdn.com/files/7ec26e8b-66b1-415a-ae62-df739bf29cdd/37996334121.pdf
- https://uploads.strikinglycdn.com/files/b9339e76-f0ef-4f2d-bdd2-f1d2dcac18e8/wumosilofivasejogoborez.pdf
- https://uploads.strikinglycdn.com/files/80504cab-ceda-4aeb-adda-f6af0c4ef04e/76067971531.pdf
- https://uploads.strikinglycdn.com/files/b124b293-0ce5-4a00-8064-5e4020f48562/19861009114.pdf
- https://uploads.strikinglycdn.com/files/12af0277-1be3-41ab-ac5d-fd256a9d34d6/westwood_t1200_for_sale.pdf
- https://uploads.strikinglycdn.com/files/3ee44f54-d2e4-4bb5-92e4-2bfb14430bc6/27667599909.pdf
- https://cdn.shopify.com/s/files/1/0502/2665/9520/files/39480347672.pdf
- https://cdn.shopify.com/s/files/1/0266/7905/0438/files/81829417130.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/nexitom.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/nafuvulivorelar.pdf
- https://pirovosarelivo.weebly.com/uploads/1/3/1/4/131406751/bafakoz-mefosatojive-vizezefazarerim-bufibojuz.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/8425062.pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/lumurefimuwav-nalexo-fewajugakeka-ributesila.pdf
- https://uploads.strikinglycdn.com/files/b4019999-6b5f-4c19-9cb9-5393e21f4fb6/76562551612.pdf
- https://uploads.strikinglycdn.com/files/b399161d-c325-4f87-b90c-ae576cb85651/40554279115.pdf
- https://uploads.strikinglycdn.com/files/e6bdeba3-bed0-454a-8376-477c41c72088/29606907279.pdf
- https://uploads.strikinglycdn.com/files/5d3e7b0b-5aba-4c0b-944b-20448f90c39d/6233082892.pdf
Embedded domains
- ggtraff.ru
- fidevawane.weebly.com
- givifajilodox.weebly.com
- xijoxamapapi.weebly.com
- rajomiluti.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- pavowojavujide.weebly.com
- bizumoku.weebly.com
- pirovosarelivo.weebly.com
- rakamukomegu.weebly.com
- vekejuritikoj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report