SUSPICIOUS — 79575628256.pdf
SUSPICIOUS — 79575628256.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
47ce5fe7b32fa30d233d8616770a9fa132386bbde20dd12210b38409762e33c5 - SHA-1:
9e701a3ca9bf5aa67d7ded4240a7f1b5adb69901 - MD5:
0d998b6101e2e9e612bfd13d2240e07b - ssdeep:
384:dsFlS3K6XgKV7cAgdOpW+0HTFzWCPBRyQ7xX3UY+DLMU1AdxCUSjro1MNa6S7eMT:BgGzpDqTFzv30hHTi6KFNEwS5CMe - TLSH:
T161309EF34457ED8C7AC6DB03ADF74559524AC78C2236976029C8772CC4BC6BDAE40A60 - Submitted as: 79575628256.pdf
- File type: pdf · Size: 37539 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=hyundai+accent+2005+repair+manual+pdf, https://uploads.strikinglycdn.com/files/ce9df12f-4cc5-40f8-88d2-0c0b9165a51b/rinoxutipidirejuv.pdf, https://uploads.strikinglycdn.com/files/5bd85283-098e-4dad-a277-063eb010f9dd/pipefixewesixizel.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=hyundai+accent+2005+repair+manual+pdf
- https://uploads.strikinglycdn.com/files/ce9df12f-4cc5-40f8-88d2-0c0b9165a51b/rinoxutipidirejuv.pdf
- https://uploads.strikinglycdn.com/files/5bd85283-098e-4dad-a277-063eb010f9dd/pipefixewesixizel.pdf
- https://uploads.strikinglycdn.com/files/5427f202-2370-44ce-a272-3a86fb36b2b7/7091766133.pdf
- http://files.studioplumpiano.com/uploads/1/3/1/3/131383497/70178f76b.pdf
- http://mifet.erosapparel.shop/uploads/1/3/0/9/130969027/mutiwazasadekob.pdf
- http://files.starlovestudio.com/uploads/1/3/2/6/132681080/2cb7cb9ac2.pdf
- http://peturo.mimijewls.com/uploads/1/3/0/7/130739873/720f4420d8.pdf
- https://uploads.strikinglycdn.com/files/60253a80-c4ec-4d2f-ae51-e49a4e14f253/51304535869.pdf
- https://uploads.strikinglycdn.com/files/77da2b4d-18ea-48d9-98ef-c842aec179e2/wowok.pdf
- https://uploads.strikinglycdn.com/files/9b0cd759-2556-49c5-921e-8bd486d73f0a/gefipemarekoxazedix.pdf
- https://uploads.strikinglycdn.com/files/aed5b029-273f-4e17-8ce3-aa0d916d848b/84903362391.pdf
- https://uploads.strikinglycdn.com/files/f79fcd96-249a-48c7-a123-f5335eaea4f0/tusazo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- files.studioplumpiano.com
- mifet.erosapparel.shop
- files.starlovestudio.com
- peturo.mimijewls.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report