SUSPICIOUS — 5487269.pdf
SUSPICIOUS — 5487269.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
48a67877bf18868ec21fdf2a430c1a1d4596dd8c99df11fa69463bb7383a3b2a - SHA-1:
87ccdaa5c0a846bd9e4c1c61426e1fa94b8eba02 - MD5:
f4ed4b3a5fa3138505f046d5d09027fc - ssdeep:
768:QgGzpD6ewuqtU9GMQNlOCBIawMSt0RAgu1dMmeSnmOR3+ZEoui:9GFOe8NGzNguEcmOsZoi - TLSH:
T18F318EF35497ED8C7ACAAB03ADF72095248AC34C6236D76045887B2CD1BC6BD7E10960 - Submitted as: 5487269.pdf
- File type: pdf · Size: 42358 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=download%20driverpack%20solution%202015%20iso, https://site-1041579.mozfiles.com/files/1041579/15206679219.pdf, https://site-1043353.mozfiles.com/files/1043353/dufukofefeverisevakuk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=download%20driverpack%20solution%202015%20iso
- https://site-1041579.mozfiles.com/files/1041579/15206679219.pdf
- https://site-1043353.mozfiles.com/files/1043353/dufukofefeverisevakuk.pdf
- https://site-1037849.mozfiles.com/files/1037849/33767341881.pdf
- https://site-1039809.mozfiles.com/files/1039809/wesik.pdf
- https://site-1036678.mozfiles.com/files/1036678/popakilamafonuligu.pdf
- https://cdn.shopify.com/s/files/1/0499/1732/9566/files/4255889537.pdf
- https://cdn.shopify.com/s/files/1/0432/0159/3502/files/wow_inscription_guide_draenor.pdf
- https://cdn.shopify.com/s/files/1/0469/0205/0978/files/liberty_ridge_farm_sunflower_festival.pdf
- https://cdn.shopify.com/s/files/1/0434/6734/1974/files/33554970470.pdf
- https://cdn.shopify.com/s/files/1/0482/5979/3057/files/73441222197.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/8101875.pdf
- https://xedaliwim.weebly.com/uploads/1/3/1/4/131454603/a923463a905e.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/6147974.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/pewaduvawafora-xubuxofibazunap-rofaras-biwaw.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f88d1ea17a31.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f88d4cba4924.pdf
- https://site-1039135.mozfiles.com/files/1039135/65401077007.pdf
- https://site-1039807.mozfiles.com/files/1039807/83010561360.pdf
- https://uploads.strikinglycdn.com/files/d5ed7d87-62a5-45fd-bd14-c248dd49b4cf/befitipajeb.pdf
- https://uploads.strikinglycdn.com/files/10ce6864-528b-475b-b88e-06c381b5b9d3/nexuvijuvebuzosodenevun.pdf
- https://uploads.strikinglycdn.com/files/706f57df-6dff-4f07-96ca-059281bd57dd/sobominorugilumege.pdf
- https://uploads.strikinglycdn.com/files/61e73c09-174b-48df-9e1c-79c5a9085b1f/66959954926.pdf
- https://uploads.strikinglycdn.com/files/943b75da-b07b-4633-9592-f4a9d2261165/7111983415.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- site-1041579.mozfiles.com
- site-1043353.mozfiles.com
- site-1037849.mozfiles.com
- site-1039809.mozfiles.com
- site-1036678.mozfiles.com
- cdn.shopify.com
- nanorobudilason.weebly.com
- xedaliwim.weebly.com
- jukafubu.weebly.com
- jufaxexave.weebly.com
- cdn-cms.f-static.net
- site-1039135.mozfiles.com
- site-1039807.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report