SUSPICIOUS — 1154090.pdf
SUSPICIOUS — 1154090.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
61f46cdc34d20e684d6f745ee8b54bc9d665a7468089d56d2ea66f98e709a6da - SHA-1:
5f26267153904746b38120a69fa4f68c71aa4645 - MD5:
7119654ccc51a037bf9f653544351174 - ssdeep:
768:1gGzpD4pP2CsanQ4GNqtybKGxBjHoC2N05Y54YiykpYIu17mUHx2gZ22JYqGrg:mGFEpQ8ae54Yiyh17hR292JYqug - TLSH:
T1F5317CF340A7ED4C7A8BAB83ADA705D960C9C3896127979049CC776CC4BC1AD3F50866 - Submitted as: 1154090.pdf
- File type: pdf · Size: 42712 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=juntar%20varias%20hojas%20pdf%20solo%20documento, https://cdn.shopify.com/s/files/1/0437/0799/0184/files/prefixes_worksheets_for_grade_2.pdf, https://cdn.shopify.com/s/files/1/0502/7269/8521/files/74898462528.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=juntar%20varias%20hojas%20pdf%20solo%20documento
- https://cdn.shopify.com/s/files/1/0483/1949/6355/files/whirlpool_undercounter_ice_maker_manual.pdf
- https://cdn.shopify.com/s/files/1/0437/0799/0184/files/prefixes_worksheets_for_grade_2.pdf
- https://cdn.shopify.com/s/files/1/0502/7269/8521/files/74898462528.pdf
- https://s3.amazonaws.com/tajimipojimo/nibexiroxuwazobopememoxa.pdf
- https://s3.amazonaws.com/tadovu/edible_mushroom_types.pdf
- https://s3.amazonaws.com/tetofamuxulil/378681876.pdf
- https://cdn-cms.f-static.net/uploads/4421042/normal_5f97581c01595.pdf
- https://cdn-cms.f-static.net/uploads/4380675/normal_5f907d79b19f1.pdf
- https://cdn-cms.f-static.net/uploads/4415748/normal_5f97a5048407d.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f8c2552d6753.pdf
- https://uploads.strikinglycdn.com/files/d0b1ecf8-37f4-4f4a-baba-ec9c3baa2a18/liduxowonenitodapiz.pdf
- https://uploads.strikinglycdn.com/files/b5a43b94-cae8-439d-94c1-327f817cff48/vomok.pdf
- https://uploads.strikinglycdn.com/files/add658f0-3dfa-48f6-92a6-1aa7e482d90a/15398491098.pdf
- https://uploads.strikinglycdn.com/files/fd656b27-8227-4811-aa19-f85b38d51d9f/72629536049.pdf
- https://uploads.strikinglycdn.com/files/691a4bf0-f349-412e-9698-654e83f44a56/lubewalibazoxosijugavo.pdf
- https://cdn-cms.f-static.net/uploads/4386597/normal_5f93c53c81735.pdf
- https://cdn-cms.f-static.net/uploads/4404520/normal_5f9798d672d4f.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f976f899272b.pdf
- https://cdn-cms.f-static.net/uploads/4375886/normal_5f8a70ebde689.pdf
- https://cdn-cms.f-static.net/uploads/4367959/normal_5f896e2a33819.pdf
- https://cdn-cms.f-static.net/uploads/4387230/normal_5f9189dec4588.pdf
- https://cdn-cms.f-static.net/uploads/4381090/normal_5f952411bb3aa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report