SUSPICIOUS — gasurelad.pdf
SUSPICIOUS — gasurelad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
0af87819d1f5f250dc31a0309f56280bd27ecf3967fbe4af66a2e4900e938ccd - SHA-1:
caf4cb6cae6291e58ebf3f69509b70d3ddaf511e - MD5:
648053c032ed84f8eb0085dba2c1df75 - ssdeep:
768:EgGzpDxJxJo6FYwFBqlBxhcZTs1mAAob3sa6kRcYGL:xGFtvtwpcZTweKF6kRcYGL - TLSH:
T16031AEF3109BED8C6ACBAF832DA6019D6149D68D7126976014DC376CC4BC2FC6F10AA1 - Submitted as: gasurelad.pdf
- File type: pdf · Size: 40176 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=betty+la+fea+capitulo+6, https://uploads.strikinglycdn.com/files/bdc4702d-7c9f-4102-871e-94dea5e94fe7/sezejudepesutonifupu.pdf, https://uploads.strikinglycdn.com/files/96caee36-4c25-41b5-b688-68e751e2d038/nafexadakukezatas.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=betty+la+fea+capitulo+6
- https://uploads.strikinglycdn.com/files/bdc4702d-7c9f-4102-871e-94dea5e94fe7/sezejudepesutonifupu.pdf
- https://uploads.strikinglycdn.com/files/96caee36-4c25-41b5-b688-68e751e2d038/nafexadakukezatas.pdf
- https://uploads.strikinglycdn.com/files/3252df75-2184-40e0-96e1-cd6d1aad34d4/78038153874.pdf
- https://uploads.strikinglycdn.com/files/d8da96c0-3e57-4006-92ba-993f332d68cf/47318670672.pdf
- https://site-1039933.mozfiles.com/files/1039933/1471766037.pdf
- https://site-1038344.mozfiles.com/files/1038344/vufonetetuzepod.pdf
- https://site-1037829.mozfiles.com/files/1037829/dexijujekikaxuxipawe.pdf
- https://site-1040347.mozfiles.com/files/1040347/24709803053.pdf
- https://uploads.strikinglycdn.com/files/8a191049-49d8-426d-a47f-1b4469ed9c2f/metutakefolifuranagow.pdf
- https://uploads.strikinglycdn.com/files/973d7656-03a1-4b56-9328-76c576f7dee4/zeberujukedutizapeve.pdf
- https://uploads.strikinglycdn.com/files/9cda89e8-c762-46e2-990d-9966b61a54a2/lexavaresibamo.pdf
- https://cdn.shopify.com/s/files/1/0435/8501/1869/files/the_spook_who_sat_by_the_door.pdf
- https://cdn.shopify.com/s/files/1/0484/0030/2240/files/lantern_corps_oaths_list.pdf
- https://cdn.shopify.com/s/files/1/0484/6845/9674/files/one_hundred_love_sonnets_xvii.pdf
- https://cdn.shopify.com/s/files/1/0484/2786/0122/files/tipos_de_metales_ferrosos.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1039933.mozfiles.com
- site-1038344.mozfiles.com
- site-1037829.mozfiles.com
- site-1040347.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report