SUSPICIOUS — 2816456.pdf
SUSPICIOUS — 2816456.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4f7a91b73cfb008773c5c187657fd7e46d45b8e57263804c7b96c1a0c65cc590 - SHA-1:
0fc1a0000bda04a035ffef9e3d62415a20696c46 - MD5:
61bb86a3b02e6cd58e09d4baf15c3d6e - ssdeep:
768:ZgGzpDbpoW8aDSZdjR4ZspqA0dky08rkkfpEN6O80xfP0wWXO2ivgI6KdvMQ68Zn:aGF/pnuZkOpqA4kvYLHQb6Kdvg84qq6 - TLSH:
T1C034AEF740A7EE8C7BCF6F1769AB14996059C788A127E35009CC272CD57C5BDAE10A20 - Submitted as: 2816456.pdf
- File type: pdf · Size: 54722 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=pokemon%20ruby%20destiny%20life%20of%20guardians%20mirage%20tower, https://uploads.strikinglycdn.com/files/67110e9f-545e-4790-a15a-41aef7a5691a/baxemadusodekolef.pdf, https://uploads.strikinglycdn.com/files/51a6703c-0c7b-4009-bbe5-beca1b4904a2/nitukopipo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=pokemon%20ruby%20destiny%20life%20of%20guardians%20mirage%20tower
- https://uploads.strikinglycdn.com/files/67110e9f-545e-4790-a15a-41aef7a5691a/baxemadusodekolef.pdf
- https://uploads.strikinglycdn.com/files/51a6703c-0c7b-4009-bbe5-beca1b4904a2/nitukopipo.pdf
- https://uploads.strikinglycdn.com/files/7e7b5365-44af-4c47-ae5c-1ea51139aba3/vasidelo.pdf
- https://uploads.strikinglycdn.com/files/f42010de-0d0e-4a78-b9ab-038c250ae187/dobumavobuz.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/zebapesuluboxaj.pdf
- https://uploads.strikinglycdn.com/files/9617421b-11c4-46f2-9dd0-b352a17bfb6c/79638502208.pdf
- https://uploads.strikinglycdn.com/files/e0929957-6b1d-48ee-ad44-5f71eb7e38ee/72534333734.pdf
- https://uploads.strikinglycdn.com/files/6f1d1e47-8383-4136-9eba-086c3b9fcf99/11892045738.pdf
- https://cdn.shopify.com/s/files/1/0484/0344/7968/files/bikarofapuwesu.pdf
- https://cdn.shopify.com/s/files/1/0482/9072/6050/files/all_my_sons_character_quotes.pdf
- https://site-1038999.mozfiles.com/files/1038999/35406897247.pdf
- https://site-1040681.mozfiles.com/files/1040681/datajiponogit.pdf
- https://site-1039224.mozfiles.com/files/1039224/40693008397.pdf
- https://site-1038982.mozfiles.com/files/1038982/43830566640.pdf
- https://site-1036737.mozfiles.com/files/1036737/21171587971.pdf
- https://cdn.shopify.com/s/files/1/0427/7246/3772/files/jujuwijigusana.pdf
- https://cdn.shopify.com/s/files/1/0433/4429/8133/files/54981512957.pdf
- https://cdn.shopify.com/s/files/1/0482/6978/7300/files/opening_scene_of_macbeth.pdf
- https://cdn.shopify.com/s/files/1/0499/9161/4614/files/batoseweri.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- xojerajap.weebly.com
- cdn.shopify.com
- site-1038999.mozfiles.com
- site-1040681.mozfiles.com
- site-1039224.mozfiles.com
- site-1038982.mozfiles.com
- site-1036737.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report