SUSPICIOUS — 55937654770.pdf
SUSPICIOUS — 55937654770.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
6d4e9f2b23fac522703e3578d6ff65e3ce6f63ff2a44c79e078cd97c43605527 - SHA-1:
df7734c53335d18b691d446316b0a9c94833cda9 - MD5:
b107a9466c87356221806b0725a4ac14 - ssdeep:
1536:7GFJd+UgMmZDlnzRtP94ahEFNDlTefmy:aFJdPgMUVV+ahEFNDlKz - TLSH:
T17A34AEF75057EE8CB7CA9B03AAEB00599186D7892172A7904088773CD5BCAFD7F40960 - Submitted as: 55937654770.pdf
- File type: pdf · Size: 54715 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=cytek+aurora+user+manual, https://site-1036719.mozfiles.com/files/1036719/94782646729.pdf, https://site-1036697.mozfiles.com/files/1036697/68389498678.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=cytek+aurora+user+manual
- https://site-1036719.mozfiles.com/files/1036719/94782646729.pdf
- https://site-1036697.mozfiles.com/files/1036697/68389498678.pdf
- https://site-1038390.mozfiles.com/files/1038390/modilixexatojumamol.pdf
- https://site-1039156.mozfiles.com/files/1039156/laxixogevunakuf.pdf
- https://site-1036639.mozfiles.com/files/1036639/75131733103.pdf
- https://uploads.strikinglycdn.com/files/d6d703c6-51c7-4c6b-87cc-57e98da562e4/wuxaxoturi.pdf
- https://uploads.strikinglycdn.com/files/a76cdf67-a106-4da3-b763-ea32dd6fa68f/39533898798.pdf
- https://uploads.strikinglycdn.com/files/794c818d-317c-4850-b254-e1dc8611e648/gexivozizuwobetovefemive.pdf
- https://uploads.strikinglycdn.com/files/d8b47d89-bebc-4697-8749-d6289d627335/67947577691.pdf
- https://uploads.strikinglycdn.com/files/73749ac8-6402-4362-a566-1a57f86b84db/60546965192.pdf
- https://site-1039187.mozfiles.com/files/1039187/34472996348.pdf
- https://site-1037101.mozfiles.com/files/1037101/86564166691.pdf
- https://site-1037916.mozfiles.com/files/1037916/fomobareba.pdf
- https://site-1036640.mozfiles.com/files/1036640/69003289935.pdf
- https://site-1037077.mozfiles.com/files/1037077/54706132027.pdf
- http://files.solutionstailored.com/uploads/1/3/1/1/131163841/5a811f025e02.pdf
- http://files.alexismariephotoanddesigns.com/uploads/1/3/0/7/130776483/7443611.pdf
- http://luzepe.msbender.com/uploads/1/3/1/8/131856097/kulezafagarosan.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1036719.mozfiles.com
- site-1036697.mozfiles.com
- site-1038390.mozfiles.com
- site-1039156.mozfiles.com
- site-1036639.mozfiles.com
- uploads.strikinglycdn.com
- site-1039187.mozfiles.com
- site-1037101.mozfiles.com
- site-1037916.mozfiles.com
- site-1036640.mozfiles.com
- site-1037077.mozfiles.com
- files.solutionstailored.com
- files.alexismariephotoanddesigns.com
- luzepe.msbender.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report