SUSPICIOUS — 62282807655.pdf
SUSPICIOUS — 62282807655.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
2d360268c472c2ce20e6d8f5b0efba97d138157825a0d50f646046fb721361aa - SHA-1:
c853cdb9843989445e2790561f54feff526455ef - MD5:
94cd23fc0e5a2100a04708f0733174fd - ssdeep:
768:PgGzpDs7rBtce7LDj7V+4S4gjTaYRcP4HmBcfBxy/Y7KIo73wzGDXtBA+Rt:4GFSp+4Xgj2W44YcoYVo7gW0+Rt - TLSH:
T14C328EF71197FC4C7A8A9F076DEB10985045E78C6132E7A048983A3CC4BCAFD6E00A61 - Submitted as: 62282807655.pdf
- File type: pdf · Size: 43848 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=fallout+shelter+best+starting+layout, https://site-1044104.mozfiles.com/files/1044104/47720230630.pdf, https://site-1037191.mozfiles.com/files/1037191/31043165233.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=fallout+shelter+best+starting+layout
- https://site-1044104.mozfiles.com/files/1044104/47720230630.pdf
- https://site-1037191.mozfiles.com/files/1037191/31043165233.pdf
- https://site-1040428.mozfiles.com/files/1040428/wometivogeruxukujak.pdf
- https://site-1036632.mozfiles.com/files/1036632/47522390739.pdf
- https://site-1036939.mozfiles.com/files/1036939/23104325525.pdf
- https://cdn.shopify.com/s/files/1/0483/9289/6663/files/12607988483.pdf
- https://cdn.shopify.com/s/files/1/0483/0252/2532/files/troy_bilt_chipper_vac.pdf
- https://site-1037909.mozfiles.com/files/1037909/5321509713.pdf
- https://site-1037885.mozfiles.com/files/1037885/67767205425.pdf
- https://site-1037069.mozfiles.com/files/1037069/18472824666.pdf
- https://site-1036852.mozfiles.com/files/1036852/wuvozujikibesuj.pdf
- https://site-1036751.mozfiles.com/files/1036751/pesiwudivin.pdf
- https://cdn.shopify.com/s/files/1/0485/9851/5872/files/delibu.pdf
- https://cdn.shopify.com/s/files/1/0430/9486/8122/files/park_valley_pool_hillsborough_nc.pdf
- https://cdn.shopify.com/s/files/1/0436/9039/3755/files/24526908191.pdf
- https://cdn.shopify.com/s/files/1/0436/9671/7977/files/ragnarok_m_hunter_leveling_guide.pdf
- https://cdn.shopify.com/s/files/1/0485/8806/2885/files/one_direction_they_dont_know_about_us_ukulele_chords.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1044104.mozfiles.com
- site-1037191.mozfiles.com
- site-1040428.mozfiles.com
- site-1036632.mozfiles.com
- site-1036939.mozfiles.com
- cdn.shopify.com
- site-1037909.mozfiles.com
- site-1037885.mozfiles.com
- site-1037069.mozfiles.com
- site-1036852.mozfiles.com
- site-1036751.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report