SUSPICIOUS — 3f3244003.pdf
SUSPICIOUS — 3f3244003.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2c45aed0827ce5dee8b9c73edc500bca64ccb5f998b91784d49eb77e26aaa640 - SHA-1:
2bee805442b5267cc4cb262b6dc061ba96fc80ec - MD5:
2f70ce0f4a19dbe953d52a0a04cc8682 - ssdeep:
1536:VGFxeyicl+pt2XOPdX2SzIcE1pNa2uc+V2v:oFxeZqEUXOPISohic+c - TLSH:
T1BF358EF34197ED4CB6CB6B43ADAB00A9609BD7896136D76444CC672CC87CAAC7F10921 - Submitted as: 3f3244003.pdf
- File type: pdf · Size: 61268 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=blackpink%20forever%20young%20song, https://cdn-cms.f-static.net/uploads/4365639/normal_5f877f02f1a2f.pdf, https://cdn-cms.f-static.net/uploads/4365589/normal_5f877023c0707.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=blackpink%20forever%20young%20song
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f877f02f1a2f.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f877023c0707.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f877233967db.pdf
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f87480b1860d.pdf
- https://uploads.strikinglycdn.com/files/f6b6d341-cc16-4706-be9e-b6af616cd3c7/44530500081.pdf
- https://uploads.strikinglycdn.com/files/768cc382-e519-432e-a445-af782f4a13f3/27119217485.pdf
- https://uploads.strikinglycdn.com/files/c69b0ec6-c43e-410b-85cf-3c63a9e9734d/duxasimijuzedav.pdf
- https://uploads.strikinglycdn.com/files/55c0ba87-56e7-47f3-938a-9d1a2b39892e/gabesofemelu.pdf
- https://uploads.strikinglycdn.com/files/4a3b5a48-84e5-415e-9fb1-2da2a9b22bff/68642195207.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/xesubezefewe.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ratefunerod.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/65bf7dd0f0f3.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/18ad995.pdf
- https://cdn.shopify.com/s/files/1/0434/2464/5272/files/free_xbox_live_codes_2015_no_surveys_no_downloads.pdf
- https://cdn.shopify.com/s/files/1/0497/3671/2346/files/vojokigeluxu.pdf
- https://cdn.shopify.com/s/files/1/0483/5753/9993/files/los_alamos_library_overdrive.pdf
- https://cdn.shopify.com/s/files/1/0266/9523/7813/files/puxekosata.pdf
- https://cdn.shopify.com/s/files/1/0498/4868/0610/files/manual_camera_fujifilm_finepix_s2950.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bewoti.pdf
- https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/8548352.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/2697538.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/xefafimofaxeparekuji.pdf
- https://punadojum.weebly.com/uploads/1/3/2/6/132680976/gowonavigevezik.pdf
- https://site-1039753.mozfiles.com/files/1039753/dosefawaxegikavipitix.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- rakamukomegu.weebly.com
- dutitujazekap.weebly.com
- tipefejiri.weebly.com
- cdn.shopify.com
- vuxozajuje.weebly.com
- dojulukasinu.weebly.com
- dimaxafazeza.weebly.com
- mojivimimujovo.weebly.com
- punadojum.weebly.com
- site-1039753.mozfiles.com
- site-1039131.mozfiles.com
- site-1042095.mozfiles.com
- site-1042937.mozfiles.com
- latestnews.fresherslive.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report