SUSPICIOUS — a86d68_96f8f33e8a4d415d8bc2e34d797d11eb.pdf
SUSPICIOUS — a86d68_96f8f33e8a4d415d8bc2e34d797d11eb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 1 of 49 detection engines flagged it.
Identification
- SHA-256:
36563e4c257970caf8e14e25ee88da71e96f9f5efdec0df1c34440567dce8a71 - SHA-1:
09c65cf2922faabd523cdc1f12a0558513389e08 - MD5:
a0686c5e07682ca5a0e26d338b3e09ef - ssdeep:
768:XgGzpDXqy6764PFE7dYoNCs/JFXgLXCXoIT27HLCcgsiCsCBb4G38JsJssYCggXX:wGFbqIbX+CYrC9snYCgcrw6x3blaaj - TLSH:
T16D33AEF71097EC4D7A8E6F137EBF105D6205D2882123AAA485D8766CC4BC6FD7E11620 - Submitted as: a86d68_96f8f33e8a4d415d8bc2e34d797d11eb.pdf
- File type: pdf · Size: 47842 bytes
- Verdict: suspicious (44/100)
Detections (1 of 49 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/wix?keyword=the+spooktacular+new+adventures+of+casper+ghost+jam, https://cdn.shopify.com/s/files/1/0480/5918/7364/files/fogele.pdf, https://cdn.shopify.com/s/files/1/0435/3658/0759/files/362157335.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=the+spooktacular+new+adventures+of+casper+ghost+jam
- https://cdn.shopify.com/s/files/1/0480/5918/7364/files/fogele.pdf
- https://cdn.shopify.com/s/files/1/0435/3658/0759/files/362157335.pdf
- https://cdn.shopify.com/s/files/1/0428/3714/7811/files/minita.pdf
- https://cdn.shopify.com/s/files/1/0431/0378/1015/files/bhakti_sagar_book_by_sharad_upadhye_free_download.pdf
- https://cdn.shopify.com/s/files/1/0433/0936/7454/files/deadpool_kills_the_marvel_universe_kickass.pdf
- https://cdn.shopify.com/s/files/1/0441/2506/1272/files/bharti_axa_term_plan.pdf
- https://cdn.shopify.com/s/files/1/0428/6503/3383/files/bigamizogaxekasazim.pdf
- http://ruzusowu.shanghaitradelink.org/uploads/1/3/0/7/130739624/pefepokolosu.pdf
- http://pibaxa.vasilisaart.com/uploads/1/3/1/3/131379246/nedoz-sukutimoguwewol-niwajebojiwikap.pdf
- http://files.tzaddi.net/uploads/1/3/2/6/132695416/c791526.pdf
- http://files.loxsalonva.com/uploads/1/3/2/6/132682106/dumapukis_rawokunata_lowasid.pdf
- http://sodafave.mrknifeguy.ca/uploads/1/3/1/8/131857758/xikasofuna.pdf
- https://cdn.shopify.com/s/files/1/0431/3553/3218/files/lupimevusibuzufujute.pdf
- https://cdn.shopify.com/s/files/1/0431/5106/5242/files/kejupuzavofirenu.pdf
- https://cdn.shopify.com/s/files/1/0431/8219/4852/files/69109589924.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- cdn.shopify.com
- ruzusowu.shanghaitradelink.org
- pibaxa.vasilisaart.com
- files.tzaddi.net
- files.loxsalonva.com
- sodafave.mrknifeguy.ca
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report