SUSPICIOUS — 7367601.pdf
SUSPICIOUS — 7367601.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
4b729fb9739fc6716616aa63f3dfc5b659223456341a3c4e43b8017eb03b3aae - SHA-1:
860e8b4423af9b11a30c5c35cd411e7e3f5a8a41 - MD5:
1dfef3b454614ebe26da13a7d8cdbf4a - ssdeep:
1536:nGFox2zcMaYyQHYiFn4WezV/J8yxuM0kQ3lagXzNwVW3zi3QWtv5+:GFoQ3YiZgV/J8yw3lnBwSids - TLSH:
T1EA36BFF3109BEC4C7ACBDB436DEA11697145DB843137DBA40898636C947C6FCAE50A21 - Submitted as: 7367601.pdf
- File type: pdf · Size: 68527 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=right%20triangle%20word%20problems%20worksheet%20with%20answers%20pdf, https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/fifasofile.pdf, https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/a8c606b473.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=right%20triangle%20word%20problems%20worksheet%20with%20answers%20pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/fifasofile.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/a8c606b473.pdf
- https://tenabawik.weebly.com/uploads/1/3/2/7/132710661/tusosufak.pdf
- https://lilawowawumoxo.weebly.com/uploads/1/3/1/4/131453384/2412298.pdf
- https://uploads.strikinglycdn.com/files/7090a2d6-65e1-49bd-b6f2-942d5456b2cd/42583260375.pdf
- https://s3.amazonaws.com/henghuili-files2/kedolipolal.pdf
- https://s3.amazonaws.com/jamokaroxoj/autodock_vina_tutorial.pdf
- https://s3.amazonaws.com/henghuili-files/north_iceland_official_tourism_guide.pdf
- https://s3.amazonaws.com/bezutu/calendario_judio_5780.pdf
- https://s3.amazonaws.com/nimuwet/savavoga.pdf
- https://cdn.shopify.com/s/files/1/0501/5987/8320/files/corporate_internet_banking_form.pdf
- https://cdn.shopify.com/s/files/1/0439/4916/2654/files/aroma_rice_cooker_instructions_4_cup.pdf
- https://cdn.shopify.com/s/files/1/0493/7108/7007/files/runik.pdf
- https://cdn.shopify.com/s/files/1/0477/0119/6966/files/folio_1040_g3_service_manual.pdf
- https://cdn.shopify.com/s/files/1/0439/5129/2584/files/37201485422.pdf
- https://cdn.shopify.com/s/files/1/0501/6515/3942/files/mookambika_stotram_in_kannada.pdf
- https://cdn.shopify.com/s/files/1/0483/3165/3273/files/82353236374.pdf
- https://xopaluwejur.weebly.com/uploads/1/3/1/8/131857284/60a3aa4394e7a.pdf
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/3554586.pdf
- https://kejedavozeve.weebly.com/uploads/1/3/1/4/131483662/gebixapitujozekida.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- jeponiruwapin.weebly.com
- jukafubu.weebly.com
- tenabawik.weebly.com
- lilawowawumoxo.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- xopaluwejur.weebly.com
- mojenosude.weebly.com
- kejedavozeve.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report