SUSPICIOUS — 90338673643.pdf
SUSPICIOUS — 90338673643.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3050833537a4a3e7fbd3c47c4eca4a5d7654d1c28849b6801296c1486240083a - SHA-1:
322a992426acaa4dcb3bf0386f85e0eb604303d8 - MD5:
1f74f098e98642eb00dcdc414973871a - ssdeep:
768:ygGzpD8GP31Iy1TZbOAHo/C4h/UPkV9WfBZh6:vGFYGboAGZhGHfBZh6 - TLSH:
T1D12F7CF35067ED4C3ACEAF17AAEA1158504AC28D7036D6A018CC776DC57CBED2E20961 - Submitted as: 90338673643.pdf
- File type: pdf · Size: 35496 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=oxford+discover+4+student%2527+s+book+pdf, https://cdn.shopify.com/s/files/1/0462/5409/6533/files/jezuvufapuxar.pdf, https://cdn.shopify.com/s/files/1/0443/0426/9468/files/leave_application_format_for_employee_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=oxford+discover+4+student%2527+s+book+pdf
- https://cdn.shopify.com/s/files/1/0462/5409/6533/files/jezuvufapuxar.pdf
- https://cdn.shopify.com/s/files/1/0443/0426/9468/files/leave_application_format_for_employee_download.pdf
- https://cdn.shopify.com/s/files/1/0435/9890/5507/files/5th_birthday_invitation_templates_for_boy.pdf
- https://cdn.shopify.com/s/files/1/0437/7378/8321/files/release_planning_template.pdf
- https://cdn.shopify.com/s/files/1/0438/9689/7704/files/welapekilifomatozif.pdf
- https://uploads.strikinglycdn.com/files/4050184e-50fc-483f-88dd-fb7bb22f2577/relotomafelof.pdf
- https://uploads.strikinglycdn.com/files/f020fbfe-ef96-4386-a286-d63804f4cea9/14009121386.pdf
- https://uploads.strikinglycdn.com/files/d17ffea5-43e7-4292-9c32-2b1e661592d6/kofagilinadalumerewologe.pdf
- https://uploads.strikinglycdn.com/files/31d58463-4ef5-4608-b247-bccbeb31b616/90315501317.pdf
- https://uploads.strikinglycdn.com/files/0f6af812-5a6d-4855-a5a3-6e7214b31d17/tubedupexopoj.pdf
- https://site-1037130.mozfiles.com/files/1037130/rusitedajufarodezigix.pdf
- https://site-1037837.mozfiles.com/files/1037837/91914778946.pdf
- https://site-1037238.mozfiles.com/files/1037238/159451193.pdf
- https://site-1037028.mozfiles.com/files/1037028/siramanilomazewifimumelin.pdf
- https://site-1036685.mozfiles.com/files/1036685/17565347207.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1037130.mozfiles.com
- site-1037837.mozfiles.com
- site-1037238.mozfiles.com
- site-1037028.mozfiles.com
- site-1036685.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report