SUSPICIOUS — 1206608405.pdf
SUSPICIOUS — 1206608405.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
4587aae58f1f0bbfc95c0c2577ee7199840a11a7e87331fe0f8571f0e7770654 - SHA-1:
f9393e3d1ac1dc8cc2cd54046936c5da598d2944 - MD5:
038119099ec48b473871fd6c27c0c975 - ssdeep:
768:ggGzpDCwI0FCS9rKkyBUX3hL+cMkqjtx+WDJ:tGF+a/X3hLYjtxbJ - TLSH:
T12D308EF7519BDC4C3A87AB03AEBA156D5049E64830379AA004C8373DC8BC3FDAE55991 - Submitted as: 1206608405.pdf
- File type: pdf · Size: 37191 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=west+central+valley+elementary+stuart+iowa, https://uploads.strikinglycdn.com/files/9e966d40-cf90-4fe3-89f9-bec267c2351f/toxafejizarerataxi.pdf, https://uploads.strikinglycdn.com/files/1d7cd7f0-57a9-4cef-b65e-f4439e78ad4f/bimegunefodivudazaviwofa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=west+central+valley+elementary+stuart+iowa
- https://uploads.strikinglycdn.com/files/9e966d40-cf90-4fe3-89f9-bec267c2351f/toxafejizarerataxi.pdf
- https://uploads.strikinglycdn.com/files/1d7cd7f0-57a9-4cef-b65e-f4439e78ad4f/bimegunefodivudazaviwofa.pdf
- https://uploads.strikinglycdn.com/files/3d865050-347f-49d9-8674-e185c67c70de/18179239602.pdf
- https://uploads.strikinglycdn.com/files/c4fa9104-adf2-4030-bf0c-8ff099a6b40e/39611001980.pdf
- https://uploads.strikinglycdn.com/files/959d7999-0895-4091-8125-bc54bd243ec7/nujokezodozanalaxawok.pdf
- https://uploads.strikinglycdn.com/files/7cb8ce39-86e2-4ebe-86c1-88d1f21626b4/22738396959.pdf
- https://uploads.strikinglycdn.com/files/26f9ec8d-58e9-4a88-8df8-b68b0b90ac36/dasitejuziv.pdf
- https://uploads.strikinglycdn.com/files/eb036805-8888-41b9-a710-5e33757ffb14/5187213347.pdf
- https://uploads.strikinglycdn.com/files/09c917ca-e50f-4174-8c11-565889ab148b/saxokuwujedusujek.pdf
- https://uploads.strikinglycdn.com/files/05786266-2bfe-4a3b-97c4-af17022f3c62/19775148058.pdf
- https://uploads.strikinglycdn.com/files/c138bec7-8ca5-428c-8fdd-1eb846dc238b/66386475490.pdf
- https://uploads.strikinglycdn.com/files/59ea43c0-0b49-4922-949d-253523d10689/94437305286.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report