SUSPICIOUS — 9973181.pdf
SUSPICIOUS — 9973181.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
265d47cdacc1396ae2aa935594fc66cecb1a625c07e87150c3bdafbf288bcf21 - SHA-1:
47593ef4d02b2632fe238cb5d562df079456356b - MD5:
af1ddfc187021a83bb18824654dcaf02 - ssdeep:
768:ogGzpD4pHBpgIcc+89q0impC0EbgPOPL26y6EsWy+brN3V705KlXkU:lGF0phjpW3L296Efy+nNFflXkU - TLSH:
T19432AFF71493ED8CBA4BAB036DEA20AA6089D3899137D754045C772DC6BC6FC6E10461 - Submitted as: 9973181.pdf
- File type: pdf · Size: 47499 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=how%20to%20reset%20a%20fitbit%20blaze, https://sozivutapadonen.weebly.com/uploads/1/3/1/1/131164462/3699b4a55a0a.pdf, https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/togatib.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=how%20to%20reset%20a%20fitbit%20blaze
- https://sozivutapadonen.weebly.com/uploads/1/3/1/1/131164462/3699b4a55a0a.pdf
- https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/togatib.pdf
- https://gapefupekud.weebly.com/uploads/1/3/1/8/131871489/ca04b876231e2c.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5058540.pdf
- https://vevejeda.weebly.com/uploads/1/3/0/7/130776099/9009541.pdf
- https://uploads.strikinglycdn.com/files/c87f6092-9c9a-4d55-94dc-53b4ba885b90/vunuvogomuzanuxamogux.pdf
- https://uploads.strikinglycdn.com/files/20c4e061-6384-4aa9-9b29-cd4015819392/jilejesomirojokavakil.pdf
- https://uploads.strikinglycdn.com/files/23b5ecdc-9b7c-4087-95bd-c0d54ab6ca51/32797523727.pdf
- https://uploads.strikinglycdn.com/files/d8dac27f-6fff-49ae-a33b-df9ff00cc4fd/32008896586.pdf
- https://cdn.shopify.com/s/files/1/0497/5362/0634/files/cuisinart_coffee_maker_dcc_3200_parts.pdf
- https://cdn.shopify.com/s/files/1/0430/9952/1178/files/diron.pdf
- https://cdn.shopify.com/s/files/1/0498/8675/7018/files/naggers_south_park.pdf
- https://cdn-cms.f-static.net/uploads/4369190/normal_5f8913b5e311a.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f877260c561b.pdf
- https://cdn-cms.f-static.net/uploads/4369777/normal_5f893a551a90d.pdf
- https://uploads.strikinglycdn.com/files/6f489b59-d5a0-4fac-995c-587abfc069ac/20017072764.pdf
- https://uploads.strikinglycdn.com/files/40b2d260-7601-4c28-8552-634680997399/mamuxokuwunurufalafanoj.pdf
- https://uploads.strikinglycdn.com/files/f24efc7a-a17f-4e89-ab58-eabb42e74f83/vipizaniwefosinatopopibep.pdf
- https://uploads.strikinglycdn.com/files/8208576d-d78a-4630-97bd-5a029c75ed03/21574063824.pdf
- https://cdn.shopify.com/s/files/1/0465/0768/8086/files/tenugisagesesidovorivutu.pdf
- https://cdn.shopify.com/s/files/1/0266/8501/4213/files/5337544023.pdf
- https://cdn.shopify.com/s/files/1/0433/4649/3605/files/blackjack_strategy_chart.pdf
- https://cdn.shopify.com/s/files/1/0434/7160/1817/files/scooter_across_america.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- sozivutapadonen.weebly.com
- jarapitoxedomel.weebly.com
- gapefupekud.weebly.com
- fijojonibiw.weebly.com
- vevejeda.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report