SUSPICIOUS — 3099202.pdf
SUSPICIOUS — 3099202.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4581d46c84bcffe1901d22a6d4b33689a479924a6fe389d12cfbe155ac46efad - SHA-1:
3237a5107e250a6d2ad9052e5ea2c417942608e3 - MD5:
04d47589560d3c718c541edf816b8cb8 - ssdeep:
768:bgGzpDWN73lSPP/Gbs3UkSG9R87KBwnuP70RS3/T7rkrPV/yOkNb5:kGFCns3UkJ9KuPH3/T/kZ/yOkNb5 - TLSH:
T1AF33BEF32197ED5C3AC66B175AB221681086C38EB0379360249DBB5DC47C6BD7E04A70 - Submitted as: 3099202.pdf
- File type: pdf · Size: 51741 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=nha%20ccma%20study%20guide%202019%20youtube, https://uploads.strikinglycdn.com/files/ca585c27-0a33-4f3d-b015-0a0624b7aa21/gakezexome.pdf, https://zeruxexo.weebly.com/uploads/1/3/4/3/134373455/ruxewivedebeteb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=nha%20ccma%20study%20guide%202019%20youtube
- https://uploads.strikinglycdn.com/files/ca585c27-0a33-4f3d-b015-0a0624b7aa21/gakezexome.pdf
- https://zeruxexo.weebly.com/uploads/1/3/4/3/134373455/ruxewivedebeteb.pdf
- https://buritovetozew.weebly.com/uploads/1/3/4/4/134486370/4476773.pdf
- https://cdn.shopify.com/s/files/1/0510/6139/1525/files/dragon_ball_broly_full_movie_reddit.pdf
- https://tenabawik.weebly.com/uploads/1/3/2/7/132710661/9612681.pdf
- https://cdn.shopify.com/s/files/1/0433/4295/4651/files/ward_co_weather_underground.pdf
- https://uploads.strikinglycdn.com/files/0235bbf4-17b8-4592-8fa2-25f0207e57ce/fuxerogikabupifoka.pdf
- https://xomevore.weebly.com/uploads/1/3/4/3/134346529/nipovubaremot_zudofotogakab_damevonedi.pdf
- https://uploads.strikinglycdn.com/files/8595a27c-4dc5-4d0e-9a29-1008b5af4fd1/safafununifod.pdf
- https://cdn-cms.f-static.net/uploads/4372073/normal_5f9230bd42221.pdf
- https://tisatazufewuvo.weebly.com/uploads/1/3/1/1/131163687/bajaxu.pdf
- https://uploads.strikinglycdn.com/files/37401663-83ae-4bd3-9aba-ca56296e8dea/669847933.pdf
- https://uploads.strikinglycdn.com/files/dd46f8fd-e218-4e4e-8e63-788d188c0605/54868400780.pdf
- https://uploads.strikinglycdn.com/files/965adb57-1139-4f22-a6e5-4f1702b49b29/battle_of_stalingrad_turning_point_in_world_war_2.pdf
- https://s3.amazonaws.com/norozovijalu/rarojesalixovovu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- zeruxexo.weebly.com
- buritovetozew.weebly.com
- cdn.shopify.com
- tenabawik.weebly.com
- xomevore.weebly.com
- cdn-cms.f-static.net
- tisatazufewuvo.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report