SUSPICIOUS — 5552995.pdf
SUSPICIOUS — 5552995.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4b8bac9c401ef23b6f74dd234ed516af1dcf39d0f75e08d1309523658160dda2 - SHA-1:
ac4aece907a3df9d46c909d61f124dee8fd6bd4e - MD5:
0771e7e631d8d9f1ceaf59e28d39ff7c - ssdeep:
768:hgGzpDwpiV+8sZLz5crR7kTIv/igt6DReJMjWO09Ly9CrwpwL+ClwKj:SGFUpo3t2B0py9wwpwL+ClwKj - TLSH:
T11C329EF3406BDC5DB6869B13ADAB11A5558EC388A137E7700888367DD1BC5BDBE04831 - Submitted as: 5552995.pdf
- File type: pdf · Size: 47095 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=stanford%2010%20practice%20test%20pdf, https://cdn.shopify.com/s/files/1/0483/8509/7877/files/4023649224.pdf, https://cdn.shopify.com/s/files/1/0487/0330/7926/files/25786007287.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=stanford%2010%20practice%20test%20pdf
- https://cdn.shopify.com/s/files/1/0483/8509/7877/files/4023649224.pdf
- https://cdn.shopify.com/s/files/1/0487/0330/7926/files/25786007287.pdf
- https://cdn.shopify.com/s/files/1/0502/8980/3461/files/guitar_tuna_mod_apk_2020.pdf
- https://site-1036935.mozfiles.com/files/1036935/19524937342.pdf
- https://site-1039299.mozfiles.com/files/1039299/gamikezebabovisusujof.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f87507b49d6f.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f876aa22ff92.pdf
- https://cdn.shopify.com/s/files/1/0484/3801/8206/files/76793747990.pdf
- https://cdn.shopify.com/s/files/1/0499/1690/3585/files/injustice_2_mod_apk_unlimited_gems_2020.pdf
- https://cdn.shopify.com/s/files/1/0439/2137/5387/files/blank_debit_cards_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0486/1172/1381/files/ham_radio_go_box_ideas.pdf
- https://cdn.shopify.com/s/files/1/0501/1328/2243/files/operators_in_programming.pdf
- https://uploads.strikinglycdn.com/files/9745e7e5-ee76-4256-bd05-8d72540f54c5/vojekeditoded.pdf
- https://uploads.strikinglycdn.com/files/5c9faa21-8b17-4949-97da-24c37ea415fc/41568933621.pdf
- https://uploads.strikinglycdn.com/files/a6729429-098c-420a-aed9-da0659cd03dc/laputifolezesuvililabasu.pdf
- https://cdn-cms.f-static.net/uploads/4366382/normal_5f872b4ed0a8e.pdf
- https://cdn-cms.f-static.net/uploads/4368243/normal_5f876b9e966ba.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f86f41ba4974.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87025fa98e1.pdf
- https://cdn-cms.f-static.net/uploads/4366630/normal_5f875f17d763c.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1036935.mozfiles.com
- site-1039299.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report