SUSPICIOUS — 92635131138.pdf
SUSPICIOUS — 92635131138.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
43525ee7525caad85312075f5b17e94722f4507f6360bda1cb92b1c379a50cdc - SHA-1:
ef4632162b118daeb9be4407c10466a4d5a1a6d8 - MD5:
f19e2477f50140f16b96f8f5dfd44732 - ssdeep:
768:HgGzpDzsElmUWW7VTI0Xe22SkPDrBzYKfQl/IFQzZ3:AGFnsDUVzXexrBnegFQzZ3 - TLSH:
T18B32BFF750A7DD4C7E8BAB0369FA20181145E7882173976055C97B3DC0BC3AD6E21AB1 - Submitted as: 92635131138.pdf
- File type: pdf · Size: 44628 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=caia+level+1+sample+exam+pdf, https://uploads.strikinglycdn.com/files/b06b18af-12d0-4257-9140-261e731f84ef/putamape.pdf, https://uploads.strikinglycdn.com/files/2655c19d-7e9c-49d5-a5dd-6008519fc9cb/20185981242.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=caia+level+1+sample+exam+pdf
- https://uploads.strikinglycdn.com/files/b06b18af-12d0-4257-9140-261e731f84ef/putamape.pdf
- https://uploads.strikinglycdn.com/files/2655c19d-7e9c-49d5-a5dd-6008519fc9cb/20185981242.pdf
- https://uploads.strikinglycdn.com/files/f5f481d1-316a-4b84-a4db-bf42d259f955/45396931763.pdf
- https://cdn.shopify.com/s/files/1/0440/6591/5032/files/pepezebaboka.pdf
- https://uploads.strikinglycdn.com/files/38b4d3e0-7b4f-4a5b-91d5-5e4ae9a59769/gakimagerog.pdf
- https://uploads.strikinglycdn.com/files/937762e0-e53f-45a6-aa25-10aefe64599d/71622538060.pdf
- https://uploads.strikinglycdn.com/files/c63afce6-d889-43bc-9569-df9d5b8ab816/xifipuwader.pdf
- https://uploads.strikinglycdn.com/files/5c62f989-3a86-40fa-a4b4-cfdda5733306/xozasopawekonuvugibetib.pdf
- https://uploads.strikinglycdn.com/files/b74e6b47-e999-465a-9f07-10760c535635/zigosiwemetitikizo.pdf
- https://uploads.strikinglycdn.com/files/6a1f4eda-184c-4a21-9f18-57672eb9856d/rawifivibixalezas.pdf
- https://uploads.strikinglycdn.com/files/282cca9a-6467-4cce-9962-ac47a463dd96/1579187729.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report