SUSPICIOUS — 329edfe.pdf
SUSPICIOUS — 329edfe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
53e99b67e0a21a68dc8970e35b7b1cdd257162b2561be99bdbdcd0def376d5e9 - SHA-1:
05a082c3918c640db1e83938b9469ef5ca4a24b1 - MD5:
0f4fb2108e739ef0aa0e85cdd18de58b - ssdeep:
768:SgGzpD6eMe+YZiYpI1g1HEqyByDrG/s4hFkvsfQcsxMy+JZ/l:PGF2efI1gdBgyL4hiveax8J1l - TLSH:
T1A2328EF31097EC4CB78BAB439DEB115A618AD38C6176D3E08498672CC4BC6BC7E10960 - Submitted as: 329edfe.pdf
- File type: pdf · Size: 46916 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=my%20little%20pony%20torture%20game, https://cdn.shopify.com/s/files/1/0432/7292/9435/files/xigurebanabudinekanir.pdf, https://cdn.shopify.com/s/files/1/0266/8924/1258/files/thus_and_so_synonym.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=my%20little%20pony%20torture%20game
- https://cdn.shopify.com/s/files/1/0432/7292/9435/files/xigurebanabudinekanir.pdf
- https://cdn.shopify.com/s/files/1/0266/8924/1258/files/thus_and_so_synonym.pdf
- https://cdn.shopify.com/s/files/1/0430/3847/4393/files/bdo_warrior_skill_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/6504/3861/files/how_to_install_mods_pokemmo_android.pdf
- https://cdn.shopify.com/s/files/1/0436/0817/8850/files/coward_the_cowardly_dog_real_story.pdf
- https://site-1043055.mozfiles.com/files/1043055/88783605236.pdf
- https://site-1044518.mozfiles.com/files/1044518/change_back_button_icon_android_action_bar.pdf
- https://site-1041694.mozfiles.com/files/1041694/xinuzix.pdf
- https://site-1038851.mozfiles.com/files/1038851/71072074336.pdf
- https://site-1036820.mozfiles.com/files/1036820/41484617198.pdf
- https://site-1038478.mozfiles.com/files/1038478/13648717909.pdf
- https://site-1039684.mozfiles.com/files/1039684/fidilibojesunivevon.pdf
- https://site-1041081.mozfiles.com/files/1041081/woody_allen_manhattan_script.pdf
- https://site-1039829.mozfiles.com/files/1039829/74590441477.pdf
- https://uploads.strikinglycdn.com/files/bc5da1ce-f6be-4e1a-b7fc-867cd50ccafe/20004953829.pdf
- https://uploads.strikinglycdn.com/files/c2919949-bd34-47ee-a938-583f620ee683/15830665055.pdf
- https://uploads.strikinglycdn.com/files/cde0d788-d3d6-4adc-8c37-b2d21d176a9b/devolugugek.pdf
- https://uploads.strikinglycdn.com/files/7b279ace-c7f3-4eab-bd72-cd6ac77c13ed/43328702231.pdf
- https://kafasomawupi.weebly.com/uploads/1/3/0/7/130775431/77cefec.pdf
- https://nosekuge.weebly.com/uploads/1/3/2/7/132740467/sutopuvuz.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xizaxamuxive.pdf
- https://nasinapalu.weebly.com/uploads/1/3/0/7/130739684/2916050.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/mikukinib.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/divili_dapixi.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1043055.mozfiles.com
- site-1044518.mozfiles.com
- site-1041694.mozfiles.com
- site-1038851.mozfiles.com
- site-1036820.mozfiles.com
- site-1038478.mozfiles.com
- site-1039684.mozfiles.com
- site-1041081.mozfiles.com
- site-1039829.mozfiles.com
- uploads.strikinglycdn.com
- kafasomawupi.weebly.com
- nosekuge.weebly.com
- dutitujazekap.weebly.com
- nasinapalu.weebly.com
- keniwuki.weebly.com
- jakedekokobara.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report