SUSPICIOUS — 616905.pdf
SUSPICIOUS — 616905.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
5dbe9fbbc5e0f1da65c7d1e8691a8f64676c5622ade1fc0268f073e3cb59eba8 - SHA-1:
cbd7cecda252a06e07eb64bfc23231752b8a42e3 - MD5:
db26c640c797adb63f603b3ebc6ac9f5 - ssdeep:
768:cgGzpD6pf1AwTGwGjh7GYI7wptMksDzi0qnYBvRokas4AWRnb559MuH+K:5GFWpfM+7Dz0nKvRokqDMuH+K - TLSH:
T1AC328DF754D7CC4C3A8BAB43BDA70664A58AC3487137DB90448C7B2DE4AC6AE3E10851 - Submitted as: 616905.pdf
- File type: pdf · Size: 43720 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=titan%20quest%20spell%20piece, https://cdn-cms.f-static.net/uploads/4377113/normal_5f8a1a56b297a.pdf, https://cdn-cms.f-static.net/uploads/4369138/normal_5f8a639267d89.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=titan%20quest%20spell%20piece
- https://cdn-cms.f-static.net/uploads/4377113/normal_5f8a1a56b297a.pdf
- https://cdn-cms.f-static.net/uploads/4369138/normal_5f8a639267d89.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8a106266324.pdf
- https://cdn-cms.f-static.net/uploads/4368954/normal_5f896ec657ad3.pdf
- https://cdn-cms.f-static.net/uploads/4372361/normal_5f89e29db786b.pdf
- https://uploads.strikinglycdn.com/files/612849fd-0303-4ca4-988b-b9a71a8548c0/fotometep.pdf
- https://uploads.strikinglycdn.com/files/0e3aba70-d4ee-40b7-a8d4-1c0c3374e476/guxisejavuladivufim.pdf
- https://uploads.strikinglycdn.com/files/57dce211-8388-4a6c-8740-c9f7c53a1585/gamepov.pdf
- https://uploads.strikinglycdn.com/files/cfc4cb80-61bc-4dd8-9098-0371fdcf391f/sosafujir.pdf
- https://uploads.strikinglycdn.com/files/8c7d4373-14a9-44f6-8d4c-6c6cc3f1b59e/23043698625.pdf
- https://uploads.strikinglycdn.com/files/a46850b6-3ade-4bf2-acc0-7cb9981cf8d8/10091401547.pdf
- https://uploads.strikinglycdn.com/files/60145fc5-f806-46e9-9bb3-e3ec7289d5bb/29072224951.pdf
- https://uploads.strikinglycdn.com/files/dd317973-29ab-4b5c-a68e-6f21228fc139/21373786054.pdf
- https://uploads.strikinglycdn.com/files/73519875-9419-44ab-a403-a35ff699b7a6/95054194920.pdf
- https://uploads.strikinglycdn.com/files/176d74b1-438c-4370-a610-a3a9992cc68b/45474832488.pdf
- https://uploads.strikinglycdn.com/files/b88d3a37-8ee9-4fdd-98de-9ce8df168a14/gajunepimogavar.pdf
- https://uploads.strikinglycdn.com/files/5c40bf92-b29e-48dc-8dbb-815629c86e61/51084186738.pdf
- https://uploads.strikinglycdn.com/files/274447a1-4737-49f4-bcfb-87ff4980dc9f/95794042873.pdf
- https://jabiratunibi.weebly.com/uploads/1/3/2/6/132683422/2967354.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/suwedevotomelasube.pdf
- https://cdn-cms.f-static.net/uploads/4366961/normal_5f891ffaf21e4.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f870c40c1bdb.pdf
- https://cdn-cms.f-static.net/uploads/4374954/normal_5f89e617a2ec3.pdf
- https://cdn-cms.f-static.net/uploads/4369179/normal_5f8a8f0771c33.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- jabiratunibi.weebly.com
- rabifupokuwu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report