SUSPICIOUS — 57695587672.pdf
SUSPICIOUS — 57695587672.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6318f661a48526d71af22e450e0afb47d5d39ec586d5ba43f7c9f1c8f2d84689 - SHA-1:
46db2dc29ce1381459797332e6134c3a520e7237 - MD5:
931b6b88082521706443d54faf35a9cb - ssdeep:
768:agGzpDYpaYcuRxWwsKUlX/OTYD2rn0ZCYFpXTOS+SOimHncepxSzPn:HGF0pkSUFxDtFpXcJJnFpxSzf - TLSH:
T1B434AFF310A3DC8C398B6B836DB751946048E6497132A36059C87B6C857C6FEAF44D72 - Submitted as: 57695587672.pdf
- File type: pdf · Size: 54728 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=ejemplos+de+aplicaciones+de+series+de+fourier, https://uploads.strikinglycdn.com/files/b495bca1-2bc9-4d65-926f-0c8bae4d7d86/1930620054.pdf, https://uploads.strikinglycdn.com/files/4399876c-85a7-4fb4-9160-5de750b21c8e/47818427383.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=ejemplos+de+aplicaciones+de+series+de+fourier
- https://uploads.strikinglycdn.com/files/b495bca1-2bc9-4d65-926f-0c8bae4d7d86/1930620054.pdf
- https://uploads.strikinglycdn.com/files/4399876c-85a7-4fb4-9160-5de750b21c8e/47818427383.pdf
- https://uploads.strikinglycdn.com/files/697a5f66-3d67-4510-b78a-8daf855e2aae/89186814898.pdf
- https://uploads.strikinglycdn.com/files/69ed1157-a39f-4ef0-93da-752f5bf6ec4b/44394181103.pdf
- http://files.impservicesmq.com/uploads/1/3/1/4/131454126/vujosibozu_fipas.pdf
- https://uploads.strikinglycdn.com/files/8f73ed29-bd2e-4437-a691-8a9f40c720c0/tezumofepov.pdf
- https://uploads.strikinglycdn.com/files/2187f51f-b1f6-4ace-81fc-94be1c8dac74/22469487104.pdf
- https://uploads.strikinglycdn.com/files/1b74ac80-bf3b-47c8-ba54-18da9da1099b/musagupolavobe.pdf
- https://uploads.strikinglycdn.com/files/7abe9aef-6c60-42e5-9c5e-f92ee44690d7/xugasagezugaxemo.pdf
- https://uploads.strikinglycdn.com/files/fe9654ab-3383-4758-9d65-1026160aadde/denedob.pdf
- https://site-1039669.mozfiles.com/files/1039669/26653152097.pdf
- https://site-1037266.mozfiles.com/files/1037266/34280924308.pdf
- https://site-1043216.mozfiles.com/files/1043216/degegejolarube.pdf
- https://site-1039602.mozfiles.com/files/1039602/wasovi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- files.impservicesmq.com
- site-1039669.mozfiles.com
- site-1037266.mozfiles.com
- site-1043216.mozfiles.com
- site-1039602.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report