SUSPICIOUS — 84221afd4b04.pdf
SUSPICIOUS — 84221afd4b04.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
5e073247e1273e82a7e0d7d1d7881b05e4de9e627002440ed5539e47d96492d8 - SHA-1:
4368e73af0b09a40a4d78631a1172f68184fc78d - MD5:
981683a63649965a47dc2fa6676b22f5 - ssdeep:
1536:lGFQpgn7XSJ3WnlXQHvhToYcW3+OWA+XPvnlAT:4FQpgDSJ8lXQHvOY0bvna - TLSH:
T1CF338DF300A7DC4C7A8BDF836DFA159D7159E6886231A7A405C8663CC8BC6BD6F10911 - Submitted as: 84221afd4b04.pdf
- File type: pdf · Size: 51676 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=www.jai%20ho%20mp3%20song, https://site-1039649.mozfiles.com/files/1039649/lagotoligovirojenuzi.pdf, https://site-1048288.mozfiles.com/files/1048288/63926754680.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=www.jai%20ho%20mp3%20song
- https://site-1039649.mozfiles.com/files/1039649/lagotoligovirojenuzi.pdf
- https://site-1048288.mozfiles.com/files/1048288/63926754680.pdf
- https://site-1038592.mozfiles.com/files/1038592/20969214912.pdf
- https://site-1044020.mozfiles.com/files/1044020/borigaxavodinagonujej.pdf
- https://site-1039768.mozfiles.com/files/1039768/64172182208.pdf
- https://site-1042843.mozfiles.com/files/1042843/45796467561.pdf
- https://cdn-cms.f-static.net/uploads/4368249/normal_5f87c87648abd.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f876589ea476.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f8715be0142a.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f871566593d6.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8715b63f3e7.pdf
- https://cdn.shopify.com/s/files/1/0496/5901/9421/files/barre3_instructor_training.pdf
- https://cdn.shopify.com/s/files/1/0480/4417/9615/files/69682275225.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/vupub_lajuwamivoban_xorunobiz.pdf
- https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/vosetalulebajob.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7885719.pdf
- https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/7605495.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/laresisif_kigadebokenub_bajutinerid.pdf
- https://site-1037111.mozfiles.com/files/1037111/bezanevetig.pdf
- https://site-1040165.mozfiles.com/files/1040165/sobasime.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- site-1039649.mozfiles.com
- site-1048288.mozfiles.com
- site-1038592.mozfiles.com
- site-1044020.mozfiles.com
- site-1039768.mozfiles.com
- site-1042843.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- fanavepuru.weebly.com
- ninukiwipovesot.weebly.com
- keniwuki.weebly.com
- genigudepa.weebly.com
- site-1037111.mozfiles.com
- site-1040165.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report