SUSPICIOUS — 271f2f.pdf
SUSPICIOUS — 271f2f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
2c606aa3aec24bda29d8ef7c03481d3836aa0b020cd8f0bab70d25c5f564eadd - SHA-1:
0702d5ecfd33ad910a2cbf9e870f90b06f67622a - MD5:
88640583ae74cdc47daf4f13b5a906b4 - ssdeep:
768:fgGzpDteqiJ3bZh+11BfcJ2jeiVmCRwxbmB3hixcIRV3qHLZz7yIgd6s:oGFBehtpiVmyCqBxs3qHdzt46s - TLSH:
T141337CF30097EC8CBA8A9B03ADBB019A514AD74C2237D7A045D8772DD47C6BDAE10D91 - Submitted as: 271f2f.pdf
- File type: pdf · Size: 48324 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=imaginarium%20mountain%20rock%20train%20set%20instructions, https://uploads.strikinglycdn.com/files/6ea0d404-1a13-426f-a59b-1983a4aa366c/98881319611.pdf, https://uploads.strikinglycdn.com/files/be73aa7f-155b-4823-91c3-ddb99f633e42/jidubanadigunuputazow.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=imaginarium%20mountain%20rock%20train%20set%20instructions
- https://uploads.strikinglycdn.com/files/6ea0d404-1a13-426f-a59b-1983a4aa366c/98881319611.pdf
- https://uploads.strikinglycdn.com/files/be73aa7f-155b-4823-91c3-ddb99f633e42/jidubanadigunuputazow.pdf
- https://uploads.strikinglycdn.com/files/0184a9a4-3e75-4db6-8796-012c5e0694ec/buvipulipasovaju.pdf
- https://uploads.strikinglycdn.com/files/1199dfba-4da9-4319-9977-b9405c011e63/41204527996.pdf
- https://cdn.shopify.com/s/files/1/0494/9884/9438/files/veggietales_the_star_of_christmas_characters.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/sadikexepifiveri.pdf
- https://cdn.shopify.com/s/files/1/0439/1731/2152/files/wasekasanaremizetik.pdf
- https://cdn.shopify.com/s/files/1/0493/7187/3446/files/89859491975.pdf
- https://cdn.shopify.com/s/files/1/0466/5281/7573/files/advanced_custom_fields_documentation.pdf
- https://cdn.shopify.com/s/files/1/0466/5281/7573/files/instantly_ageless_application_instructions.pdf
- https://cdn.shopify.com/s/files/1/0467/7763/0873/files/water_hammer_in_pipes.pdf
- https://cdn.shopify.com/s/files/1/0430/3604/9571/files/craigslist_cleveland_boats.pdf
- https://cdn.shopify.com/s/files/1/0437/4953/9989/files/48706724751.pdf
- https://uploads.strikinglycdn.com/files/6644ca64-facf-45d1-b9e6-6f30b41f359a/nuvapikitegezekekeg.pdf
- https://uploads.strikinglycdn.com/files/21572442-484d-402c-b43b-c48c486df924/jezabizozirokuwazegemib.pdf
- https://uploads.strikinglycdn.com/files/942e9d34-3e08-40a3-9ecf-834822e31cdd/36113674335.pdf
- https://uploads.strikinglycdn.com/files/e64c9066-6b91-4c6a-bc98-8fd96e610c47/nodefuwutubuwexana.pdf
- https://uploads.strikinglycdn.com/files/159490b3-4e16-4f98-8aed-7fbc420195b4/15220623619.pdf
- https://dofazodasi.weebly.com/uploads/1/3/0/8/130873943/lozonen.pdf
- https://zugufavowi.weebly.com/uploads/1/3/0/8/130874222/f3ae0daca226dc.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/xofadakigosesatedeb.pdf
- https://uploads.strikinglycdn.com/files/0e002361-c001-4307-9b9e-8d29a6a84275/pusebovazosawomivimedito.pdf
- https://uploads.strikinglycdn.com/files/fe8182cc-4d8d-41f6-8b3c-49392be1cd53/43699316261.pdf
- https://uploads.strikinglycdn.com/files/ac3a33f0-6663-4b88-b0fe-20b2bcd75da5/41233824124.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- dofazodasi.weebly.com
- zugufavowi.weebly.com
- tivakoxidedopa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report