SUSPICIOUS — 29feca687d.pdf
SUSPICIOUS — 29feca687d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
33c9517b58d8754ce4976809f672578ce4d72150126e44ae7350b1dbcbb44d7e - SHA-1:
d7aff45cc83fd60eaf8f07d3426c724f480b79e5 - MD5:
85344a60cecc68d54b6f713b652723f3 - ssdeep:
768:ysgGzpD3pSvAcv1LsgdeEXYoxvpmLzUUvoNibKqLq1NKoj07tFC:WGFLpjRL0NKT7tFC - TLSH:
T1D4307DF354ABED8C7B87AB436DEB15665089C38C6237D750498C2B2CD5AC6BDBE00850 - Submitted as: 29feca687d.pdf
- File type: pdf · Size: 37970 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=mysterious%20island%20of%20beautiful%20woman, https://site-1043132.mozfiles.com/files/1043132/kifakagepizawemavef.pdf, https://site-1038905.mozfiles.com/files/1038905/7025653080.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=mysterious%20island%20of%20beautiful%20woman
- https://site-1043132.mozfiles.com/files/1043132/kifakagepizawemavef.pdf
- https://site-1038905.mozfiles.com/files/1038905/7025653080.pdf
- https://site-1039400.mozfiles.com/files/1039400/mitutelezuzevuj.pdf
- https://site-1040595.mozfiles.com/files/1040595/biforovinobavejuwu.pdf
- https://cdn.shopify.com/s/files/1/0480/9297/1172/files/bashar_transformative_shifting.pdf
- https://cdn.shopify.com/s/files/1/0497/9625/1810/files/58399461182.pdf
- https://cdn.shopify.com/s/files/1/0482/2653/3528/files/65623996226.pdf
- https://cdn.shopify.com/s/files/1/0497/4385/5777/files/lampedusa_cross_wikipedia.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f87621fcbf93.pdf
- https://cdn-cms.f-static.net/uploads/4366308/normal_5f874ad2b7723.pdf
- https://cdn-cms.f-static.net/uploads/4368782/normal_5f878124ec056.pdf
- https://cdn.shopify.com/s/files/1/0498/7024/1953/files/50157391687.pdf
- https://cdn.shopify.com/s/files/1/0481/6610/9335/files/velizowezupe.pdf
- https://cdn.shopify.com/s/files/1/0429/1588/9305/files/41755524503.pdf
- https://cdn.shopify.com/s/files/1/0481/8717/9160/files/woparisikovizaforozitase.pdf
- https://cdn.shopify.com/s/files/1/0432/6676/9058/files/ortografa_de_la_lengua_espaola_2015.pdf
- https://cdn.shopify.com/s/files/1/0490/0805/0343/files/39407171305.pdf
- https://cdn.shopify.com/s/files/1/0498/0693/4178/files/63175095342.pdf
- https://cdn.shopify.com/s/files/1/0502/8249/6173/files/zoraterob.pdf
- https://uploads.strikinglycdn.com/files/729b008d-23aa-4a85-b648-88199afef63d/23189109664.pdf
- https://uploads.strikinglycdn.com/files/0034bef7-19c4-4bfc-84f1-b687cd6583bc/30647722938.pdf
- https://uploads.strikinglycdn.com/files/435d1085-8068-4f16-8fce-dbbaf20bb2b6/10757389729.pdf
- https://uploads.strikinglycdn.com/files/e1d29624-d57e-4740-aaf0-3575b514be2d/22237795973.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- site-1043132.mozfiles.com
- site-1038905.mozfiles.com
- site-1039400.mozfiles.com
- site-1040595.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report