SUSPICIOUS — 84257482848.pdf
SUSPICIOUS — 84257482848.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
02c0a6ce7ea1d34a487c5c5af502e0f74a174665d0154d6453f25bd777cdf292 - SHA-1:
89e752485dd86ab0b9bd66fa368ea4cd19ffe82f - MD5:
a29c9f1c086e1f81e6f57ef2b2fc854a - ssdeep:
768:UgGzpDQNDI8bIR3Ai7125hQ1b3/+terUqVX28by4wPZIw4:hGFED0z7AQ1b3/+oVX2jPZIw4 - TLSH:
T124318CF7119BDE4C39875B43ADAA1188A18BC3883123A760598C7B7DE4786FC7F41861 - Submitted as: 84257482848.pdf
- File type: pdf · Size: 41416 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=ultrasump+3+manual, https://site-1038890.mozfiles.com/files/1038890/26940427621.pdf, https://site-1045390.mozfiles.com/files/1045390/6234451287.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=ultrasump+3+manual
- https://site-1038890.mozfiles.com/files/1038890/26940427621.pdf
- https://site-1045390.mozfiles.com/files/1045390/6234451287.pdf
- https://site-1037077.mozfiles.com/files/1037077/41973882159.pdf
- https://site-1041413.mozfiles.com/files/1041413/15244796163.pdf
- https://uploads.strikinglycdn.com/files/e919c060-dd73-4394-b455-2d00004b456b/86643860611.pdf
- https://uploads.strikinglycdn.com/files/fdbbe9e0-4053-4d15-9d74-cdfaaa7a4a32/39825367811.pdf
- https://uploads.strikinglycdn.com/files/8c4f18dc-3881-499d-b231-b65ba1adfe76/podufugazawegokeni.pdf
- https://uploads.strikinglycdn.com/files/a75ae237-2f4e-41f8-8253-0c69c89c531d/lirurofaletixa.pdf
- https://uploads.strikinglycdn.com/files/e4383c33-9c0a-4f6a-8d08-b85ed554987e/tabipuwusidifipikitaf.pdf
- https://uploads.strikinglycdn.com/files/501c3818-0241-4bf5-b428-e32041fefdd6/zixisus.pdf
- https://uploads.strikinglycdn.com/files/55008859-ceeb-43de-b178-12bcf6c2a6bf/tejuzazumuxezat.pdf
- https://uploads.strikinglycdn.com/files/bdb96649-3444-4389-8275-985eea46f233/situjawiwo.pdf
- http://files.hardawayart.com/uploads/1/3/0/7/130739169/govoro.pdf
- http://resij.catieburden.com/uploads/1/3/2/8/132814241/kesuxidu_ludakuwupodule_zobupoveve.pdf
- http://wuwamux.straushistoricalsociety.org/uploads/1/3/0/7/130774979/b2438b55a2d54.pdf
- http://files.fixiology.org/uploads/1/3/1/4/131483445/5b5103a3a10.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1038890.mozfiles.com
- site-1045390.mozfiles.com
- site-1037077.mozfiles.com
- site-1041413.mozfiles.com
- uploads.strikinglycdn.com
- files.hardawayart.com
- resij.catieburden.com
- wuwamux.straushistoricalsociety.org
- files.fixiology.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report