SUSPICIOUS — 8580990.pdf
SUSPICIOUS — 8580990.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3a30070e4a1a9bb2a4207e2a593cd0d5f86d8575acda0d1e2ead2ae200aa9b61 - SHA-1:
a51ab001e22117355a74d9fdc2559acc868053eb - MD5:
a4e47bfef159aab46411456355217553 - ssdeep:
768:+gGzpDSpMgzxSmvuzJmrgUu5zfUuaKsYlooA4FSklA2E7oprwzHm41DOGDB9F4:7GFep5cTCKXFPSklAIeK2rDB9F4 - TLSH:
T16B328DF310A7ED4CB98B9B53ACAB12564099C78D6232E32085D8B76DD47C6BD7E00871 - Submitted as: 8580990.pdf
- File type: pdf · Size: 44457 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=jewellery%20certificate%20of%20authenticity%20template, https://site-1041411.mozfiles.com/files/1041411/gebumumuzosaf.pdf, https://site-1041587.mozfiles.com/files/1041587/oracle_11g_oca_certification_books.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=jewellery%20certificate%20of%20authenticity%20template
- https://site-1041411.mozfiles.com/files/1041411/gebumumuzosaf.pdf
- https://site-1041587.mozfiles.com/files/1041587/oracle_11g_oca_certification_books.pdf
- https://site-1044240.mozfiles.com/files/1044240/70516167740.pdf
- https://site-1048573.mozfiles.com/files/1048573/17989661058.pdf
- https://cdn.shopify.com/s/files/1/0433/4131/6264/files/leridobiwovudonawirekod.pdf
- https://cdn.shopify.com/s/files/1/0494/9337/7183/files/84774630271.pdf
- https://site-1038728.mozfiles.com/files/1038728/17193661106.pdf
- https://site-1039654.mozfiles.com/files/1039654/teruwosanevalegofipatod.pdf
- https://site-1048479.mozfiles.com/files/1048479/52405012093.pdf
- https://site-1048476.mozfiles.com/files/1048476/vudojanekenoxuladak.pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f874da369cf4.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f88bc5fa98df.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f8715e81fb1b.pdf
- https://cdn-cms.f-static.net/uploads/4369648/normal_5f88bae5f384f.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f874e0baf9e2.pdf
- https://site-1043087.mozfiles.com/files/1043087/porezujasusabozuzekukivew.pdf
- https://site-1040665.mozfiles.com/files/1040665/2149367291.pdf
- https://site-1043843.mozfiles.com/files/1043843/8740382644.pdf
- https://nafeziwubiwodi.weebly.com/uploads/1/3/1/3/131379183/7a9a0e714ae.pdf
- https://zelapagetuwuj.weebly.com/uploads/1/3/1/4/131406140/pakexidusunokaxejef.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/3794757.pdf
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/4384628.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/jibepare-vudaramuzi-refirezagulele.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- site-1041411.mozfiles.com
- site-1041587.mozfiles.com
- site-1044240.mozfiles.com
- site-1048573.mozfiles.com
- cdn.shopify.com
- site-1038728.mozfiles.com
- site-1039654.mozfiles.com
- site-1048479.mozfiles.com
- site-1048476.mozfiles.com
- cdn-cms.f-static.net
- site-1043087.mozfiles.com
- site-1040665.mozfiles.com
- site-1043843.mozfiles.com
- nafeziwubiwodi.weebly.com
- zelapagetuwuj.weebly.com
- bedizegoresupa.weebly.com
- kupugaxome.weebly.com
- mogilifus.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report