SUSPICIOUS — 92651242711.pdf
SUSPICIOUS — 92651242711.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
4107e76ceb0d2017b50d6519cbbfe13aed54ab4b802a464e4843fbec1d65b5a2 - SHA-1:
22b26d2c7799a4afb4d4690cd5031c2fd3f9fc22 - MD5:
4f5bd6484ce6eef208db49f892518dab - ssdeep:
768:DgGzpDOpdD3IxX83K/ogEytU7THa8o7v/sP/VZFZrUQ9UfEkXzTzWg6p7C:8GFKpdDo7HsPdZFlUQGXrl6pO - TLSH:
T1A933AFF350A7ED8C398B6B476DAB0099755AC7CD21229B9005CC672CD4BCBEDAF10660 - Submitted as: 92651242711.pdf
- File type: pdf · Size: 48662 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/pify?keyword=fashion+design+sketches+pdf+download, https://uploads.strikinglycdn.com/files/6293731f-8f76-4008-b641-fad8d40f7d51/luxopizopozokure.pdf, https://uploads.strikinglycdn.com/files/1dd5aa6f-9be7-4ec5-9035-5e6dae138dc4/jixufonugorurigidanelovi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/pify?keyword=fashion+design+sketches+pdf+download
- https://uploads.strikinglycdn.com/files/6293731f-8f76-4008-b641-fad8d40f7d51/luxopizopozokure.pdf
- https://uploads.strikinglycdn.com/files/1dd5aa6f-9be7-4ec5-9035-5e6dae138dc4/jixufonugorurigidanelovi.pdf
- https://uploads.strikinglycdn.com/files/50e238d2-a458-4061-a092-5f669ea7ea63/76715931121.pdf
- https://site-1040571.mozfiles.com/files/1040571/52445919702.pdf
- https://site-1040250.mozfiles.com/files/1040250/birugopasegivil.pdf
- https://cdn.shopify.com/s/files/1/0431/8475/0747/files/dibobixuzuwofebotafax.pdf
- https://cdn.shopify.com/s/files/1/0496/7795/9325/files/avicii_the_days_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0437/5448/7957/files/understanding_machine_learning_from_theory_to_algorithms_solution_manual.pdf
- https://cdn.shopify.com/s/files/1/0435/2973/2245/files/viruzuz.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f86f43d9d918.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f8700ca3c1b1.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f86fad88c1d9.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f86f93d6f527.pdf
- https://site-1039837.mozfiles.com/files/1039837/68627026643.pdf
- https://site-1044243.mozfiles.com/files/1044243/zudabopibe.pdf
- https://site-1039817.mozfiles.com/files/1039817/43087938615.pdf
- https://site-1036880.mozfiles.com/files/1036880/mekebu.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f86f8c3b62e2.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f86f5a1a636a.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f86fafc4399b.pdf
- https://cdn-cms.f-static.net/uploads/4366015/normal_5f86fedf98283.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1040571.mozfiles.com
- site-1040250.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1039837.mozfiles.com
- site-1044243.mozfiles.com
- site-1039817.mozfiles.com
- site-1036880.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report