SUSPICIOUS — 15200663273.pdf
SUSPICIOUS — 15200663273.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
20f3a851fd13fccac474b8a27b03a2bf179f5ae8324e5f0761d55050ae3d47b1 - SHA-1:
437ae0560f479181eb6d76f2287b9534d9ea7b3f - MD5:
270bebe3d333de9f7a47316fa97825e3 - ssdeep:
768:RgGzpD6PU1zm24T84jDYQ0OEzypQkES576bqnDSjw3dXlPWPNMk:iGF6K54T3YVwakEfbIOjw35lPkNMk - TLSH:
T12B319EF39097DD8C77C6AB439CB70169709A97897173AAA414E9776CC87C3BC6E00920 - Submitted as: 15200663273.pdf
- File type: pdf · Size: 42928 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=tecumseh+5+hp+engine+manual, https://site-1036750.mozfiles.com/files/1036750/gasuboze.pdf, https://site-1039513.mozfiles.com/files/1039513/84640012050.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=tecumseh+5+hp+engine+manual
- https://site-1036750.mozfiles.com/files/1036750/gasuboze.pdf
- https://site-1039513.mozfiles.com/files/1039513/84640012050.pdf
- https://site-1037124.mozfiles.com/files/1037124/fixex.pdf
- https://site-1037125.mozfiles.com/files/1037125/53485021413.pdf
- https://site-1043603.mozfiles.com/files/1043603/fapenabezaxujo.pdf
- https://site-1036833.mozfiles.com/files/1036833/28625534030.pdf
- https://site-1037883.mozfiles.com/files/1037883/28253387648.pdf
- https://site-1038827.mozfiles.com/files/1038827/43547549081.pdf
- https://site-1036636.mozfiles.com/files/1036636/fikerafar.pdf
- https://uploads.strikinglycdn.com/files/633087ab-4645-4bd2-84ff-5adbc8205ce0/4326374202.pdf
- https://uploads.strikinglycdn.com/files/31d2b9e2-61b5-44ec-884d-4f6322e0d9d5/19026019551.pdf
- https://uploads.strikinglycdn.com/files/d20ebe43-ab1e-4337-a090-bf7513ab6cfc/tugifizokazafi.pdf
- https://uploads.strikinglycdn.com/files/ce2ce52e-eb7f-43ef-9d10-5d2d785311b4/kitofasalawowod.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1036750.mozfiles.com
- site-1039513.mozfiles.com
- site-1037124.mozfiles.com
- site-1037125.mozfiles.com
- site-1043603.mozfiles.com
- site-1036833.mozfiles.com
- site-1037883.mozfiles.com
- site-1038827.mozfiles.com
- site-1036636.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report