SUSPICIOUS — 3020588.pdf
SUSPICIOUS — 3020588.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
03e44f98c53797d0906e84bc26f3f32bc4f76e1d65904133e9ef035b1052681f - SHA-1:
5355d8a9a683a6545dc53a0610d1fa296800202e - MD5:
c3732b9226c0a84031ef4b49ff85fb8d - ssdeep:
768:vgGzpDgGe+J0PMqt623X70CqyRgeRNDVzRWErjnUaA3C4+30kmduE2Rhg/23fAbz:YGF3eYm7zgIND5Hnp3i4Rhg/KAbz - TLSH:
T16033AEF354A7ED8C3A866B2368F311656186C78C723AEB60448DB23CD47C7BD6E14960 - Submitted as: 3020588.pdf
- File type: pdf · Size: 51249 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=worse%20than%20slavery%20david%20oshinsky%20pdf, https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/fuvogejub.pdf, https://porelananov.weebly.com/uploads/1/3/0/7/130775759/896334cc5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=worse%20than%20slavery%20david%20oshinsky%20pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/fuvogejub.pdf
- https://porelananov.weebly.com/uploads/1/3/0/7/130775759/896334cc5.pdf
- https://gumomamomav.weebly.com/uploads/1/3/1/3/131398069/6348655.pdf
- https://uploads.strikinglycdn.com/files/3cf6657a-6df5-4301-b384-76372d4f58a7/migazotawifopesefep.pdf
- https://uploads.strikinglycdn.com/files/d9a4d115-8631-4c21-91c3-d2b9b29ee409/cpu-z_apk_download_for_windows_10.pdf
- https://uploads.strikinglycdn.com/files/6b14aa6a-e60b-4f74-96ee-2d33819818a9/wogiv.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f8722de5af8b.pdf
- https://cdn-cms.f-static.net/uploads/4380859/normal_5f8eb2cf709dc.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f935a0e13842.pdf
- https://uploads.strikinglycdn.com/files/df830e92-0be7-4caf-a29f-f85070f0e8ac/what_does_wym_mean_on_snap.pdf
- https://uploads.strikinglycdn.com/files/37ffc9c4-c7b2-46be-932e-7ffde70d952c/votuwiwaxijapuxobogizuf.pdf
- https://uploads.strikinglycdn.com/files/20b6602c-3e31-497a-a81c-48a5defb89cf/pandigital_panscn06_driver.pdf
- https://uploads.strikinglycdn.com/files/19000073-a861-4d70-b517-a924d6d61f5b/38312085615.pdf
- https://uploads.strikinglycdn.com/files/ecb7cde9-e813-4c0d-8d3c-b21f86e7f4ae/lidajivenopuluzolon.pdf
- https://cdn.shopify.com/s/files/1/0495/1565/9430/files/what_does_en_stand_for_in_standards.pdf
- https://cdn.shopify.com/s/files/1/0433/9371/2286/files/36931460759.pdf
- https://cdn.shopify.com/s/files/1/0498/3232/9371/files/japanese_sword_names_anime.pdf
- https://cdn.shopify.com/s/files/1/0439/2094/9403/files/rimofubiwawivumumisuga.pdf
- https://cdn.shopify.com/s/files/1/0433/0219/1269/files/rugizubufemat.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- dutitujazekap.weebly.com
- porelananov.weebly.com
- gumomamomav.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report