SUSPICIOUS — 2489123.pdf
SUSPICIOUS — 2489123.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
379d2c05936a65b817c892d8621471b106b3c49ce763f909e919a0971ff3fa75 - SHA-1:
2286deca84abcdc85300d1313bc273a58a9f1706 - MD5:
476cbdba0a033a002147e69f4cd0101e - ssdeep:
1536:TGF/pZc6CIFmoexLm/BGYTProYFSW+I1bW:iF/pDCIHqmwYjrlHrs - TLSH:
T1B036CFF304A7EC4CB9CBAB535CAA02566199D3847237E7948488776CD9BC6BCBF00950 - Submitted as: 2489123.pdf
- File type: pdf · Size: 63811 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=bloquer%20ticket%20restaurant, https://site-1048205.mozfiles.com/files/1048205/dabopepetimotidado.pdf, https://site-1042843.mozfiles.com/files/1042843/99363707592.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=bloquer%20ticket%20restaurant
- https://site-1048205.mozfiles.com/files/1048205/dabopepetimotidado.pdf
- https://site-1042843.mozfiles.com/files/1042843/99363707592.pdf
- https://site-1043970.mozfiles.com/files/1043970/47603983866.pdf
- https://site-1043165.mozfiles.com/files/1043165/tajukexiwigonakuxudemavis.pdf
- https://site-1040974.mozfiles.com/files/1040974/88885774329.pdf
- https://site-1041074.mozfiles.com/files/1041074/womuruzefugutogovekabode.pdf
- https://site-1040104.mozfiles.com/files/1040104/50433054699.pdf
- https://site-1043908.mozfiles.com/files/1043908/pedimezokuraxulale.pdf
- https://site-1043705.mozfiles.com/files/1043705/fisozejowujudulujipifuta.pdf
- https://site-1037268.mozfiles.com/files/1037268/81944917518.pdf
- https://uploads.strikinglycdn.com/files/85ff8487-8a23-4d76-abfa-6eb3b9f1b091/jufidizujolijafunixila.pdf
- https://uploads.strikinglycdn.com/files/518e89c7-f8bf-4d49-957a-a10becced162/36794176086.pdf
- https://uploads.strikinglycdn.com/files/81f7871b-ee62-46c6-9413-4252d6069af1/nutogu.pdf
- https://site-1037156.mozfiles.com/files/1037156/kenutetupezepo.pdf
- https://site-1036796.mozfiles.com/files/1036796/reruwaxesi.pdf
- https://uploads.strikinglycdn.com/files/925a660c-dd2d-453e-9261-24a3a5084db1/74339456385.pdf
- https://uploads.strikinglycdn.com/files/7e001e4b-de0c-4acb-ab1f-d52596e7ab97/30359842033.pdf
- https://uploads.strikinglycdn.com/files/29d38826-f5e3-4ff3-9539-176544b46d74/sogikanabedulanox.pdf
- https://uploads.strikinglycdn.com/files/a91082d8-1ef0-4a17-9e35-b4c6ecc294f3/bekomiwironovalole.pdf
- https://cdn.shopify.com/s/files/1/0437/9371/1265/files/plot_graphic_organizer_2nd_grade.pdf
- https://cdn.shopify.com/s/files/1/0428/0736/1703/files/gokunelivukofe.pdf
- https://cdn.shopify.com/s/files/1/0492/8611/9580/files/gabriels_oboe_piano_sheet_music_free_download.pdf
- https://cdn.shopify.com/s/files/1/0435/7544/3615/files/ruvuvuraweviziwise.pdf
- https://cdn.shopify.com/s/files/1/0433/7706/6135/files/control_systems_engineering_6th_edition_solutions_manual.pdf
Embedded domains
- ggtraff.ru
- site-1048205.mozfiles.com
- site-1042843.mozfiles.com
- site-1043970.mozfiles.com
- site-1043165.mozfiles.com
- site-1040974.mozfiles.com
- site-1041074.mozfiles.com
- site-1040104.mozfiles.com
- site-1043908.mozfiles.com
- site-1043705.mozfiles.com
- site-1037268.mozfiles.com
- uploads.strikinglycdn.com
- site-1037156.mozfiles.com
- site-1036796.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report