SUSPICIOUS — 2718646.pdf
SUSPICIOUS — 2718646.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
347c6a3145409d568dbf8b039a882f9a94bc40d9e0b5535a3556617e0668f19b - SHA-1:
4b1be57a816707771b27f636be4ca6b48e57ff38 - MD5:
e039ea614ecf6de73932962c6adaf2e5 - ssdeep:
768:BgGzpD/QG6uAmpXaiGPwi0sN9f1ObndcLlO5ndt2RgizkceUgFF6/qyfGZCgXJmp:yGFTbGPYsfIeundt2uiAUL/qyOZrXgf - TLSH:
T166338CF35097DC8D3A83EF435DBB18999098D688323297605498B77CC87C6ADBF01961 - Submitted as: 2718646.pdf
- File type: pdf · Size: 49252 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=musashi%20pdf%20romana, https://xumolatakikekum.weebly.com/uploads/1/3/4/3/134335049/rogezewuboku.pdf, https://mawoluji.weebly.com/uploads/1/3/4/2/134265904/fazaxixodawavi-kavex-disoto.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=musashi%20pdf%20romana
- https://xumolatakikekum.weebly.com/uploads/1/3/4/3/134335049/rogezewuboku.pdf
- https://mawoluji.weebly.com/uploads/1/3/4/2/134265904/fazaxixodawavi-kavex-disoto.pdf
- https://xotuwajugi.weebly.com/uploads/1/3/4/3/134349857/7689111.pdf
- https://s3.amazonaws.com/nowokil/temporal_convolutional_networks.pdf
- https://venifamu.weebly.com/uploads/1/3/4/5/134501621/6654d6c9914c4.pdf
- https://cdn.shopify.com/s/files/1/0432/5782/3390/files/bikofo.pdf
- https://jajigasusugase.weebly.com/uploads/1/3/4/2/134234637/dapuxenuga.pdf
- https://cdn.shopify.com/s/files/1/0500/2369/4506/files/benelli_m4_shotgun_forend.pdf
- https://cdn.shopify.com/s/files/1/0479/7956/1130/files/free_rate_confirmation_template.pdf
- https://ganusanawopat.weebly.com/uploads/1/3/4/4/134488834/pipodofesugimibunip.pdf
- https://cdn.shopify.com/s/files/1/0430/9640/8218/files/sivitite.pdf
- https://cdn.shopify.com/s/files/1/0266/8966/7254/files/minecraft_pocket_edition_11.1_apk_download_0.16.0.pdf
- https://felomogolupa.weebly.com/uploads/1/3/4/3/134345494/1b89e601a513e41.pdf
- https://cdn.shopify.com/s/files/1/0497/8219/4338/files/blackfin_walkie_talkie_manual.pdf
- https://cdn.shopify.com/s/files/1/0500/1032/5150/files/rijuwibumi.pdf
- https://bakukumi.weebly.com/uploads/1/3/4/4/134437371/vezef.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- xumolatakikekum.weebly.com
- mawoluji.weebly.com
- xotuwajugi.weebly.com
- s3.amazonaws.com
- venifamu.weebly.com
- cdn.shopify.com
- jajigasusugase.weebly.com
- ganusanawopat.weebly.com
- felomogolupa.weebly.com
- bakukumi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report