SUSPICIOUS — 55639279937.pdf
SUSPICIOUS — 55639279937.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4362df898de08af92a01878bd87faab185317e5ef96dc10b2bbf06c463c19e15 - SHA-1:
87d0f89d3891837125a5641ec579f3c90b915d55 - MD5:
4fc242d17dd0057fd020dafe24f0756d - ssdeep:
768:zgGzpDyr7KB8pLKwm+e9KyNT7bkRPILoOtEwwm:MGF+r7Q57oRPILoOtEwwm - TLSH:
T1FF2F8DF35067EC8CB64AAB036EE6015A5199CB4D7133966058D87B3DC4BC6FE3E10A60 - Submitted as: 55639279937.pdf
- File type: pdf · Size: 35304 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=gucci+watches+code+ref+1142+price, https://site-1038351.mozfiles.com/files/1038351/96112979179.pdf, https://site-1037922.mozfiles.com/files/1037922/59107563772.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=gucci+watches+code+ref+1142+price
- https://site-1038351.mozfiles.com/files/1038351/96112979179.pdf
- https://site-1037922.mozfiles.com/files/1037922/59107563772.pdf
- https://site-1037024.mozfiles.com/files/1037024/73602898649.pdf
- https://site-1037848.mozfiles.com/files/1037848/fuveviguzuzexaxutowulasis.pdf
- https://site-1039711.mozfiles.com/files/1039711/roxibefevamuzudimat.pdf
- https://cdn.shopify.com/s/files/1/0484/8327/0818/files/marble_launcher_projectile_lab.pdf
- https://cdn.shopify.com/s/files/1/0434/1301/2630/files/jenunemopu.pdf
- http://files.chawkscatering.com/uploads/1/3/0/8/130874075/25178.pdf
- http://files.pattilooneyphotography.com/uploads/1/3/0/7/130776589/wijonagufaw.pdf
- http://diwujupev.skylineelectricmn.com/uploads/1/3/1/4/131482826/4999387.pdf
- http://muxof.quickfiretalent.com/uploads/1/3/1/4/131453060/jenem-donegekame-farakafivaz-pinusaxasi.pdf
- https://cdn.shopify.com/s/files/1/0430/5072/9634/files/stream_pacquiao_vs_thurman_free_reddit.pdf
- https://cdn.shopify.com/s/files/1/0433/9102/5306/files/1083393768.pdf
- https://cdn.shopify.com/s/files/1/0486/2630/3134/files/64334124564.pdf
- https://cdn.shopify.com/s/files/1/0465/0860/5590/files/simple_batch_system_in_operating_system.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1038351.mozfiles.com
- site-1037922.mozfiles.com
- site-1037024.mozfiles.com
- site-1037848.mozfiles.com
- site-1039711.mozfiles.com
- cdn.shopify.com
- files.chawkscatering.com
- files.pattilooneyphotography.com
- diwujupev.skylineelectricmn.com
- muxof.quickfiretalent.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report