SUSPICIOUS — 87688224360.pdf
SUSPICIOUS — 87688224360.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6e4fcd18e1dbc9576bcb7cbc521e6c67b3bff04612c0a689a3f00e85214c3a89 - SHA-1:
27b53ee9bbb1b5cac5c6394dd579602d64f15371 - MD5:
bcd99b80fbf9719532034ed7db6e52b0 - ssdeep:
1536:lGFw90jt40LRap3uY0+f++K+hlgN8G18uGNtg390aSs8Tre84dUXqkSsE4B:4Fw9g9geYHY+h+N8/By3kTre7AqkHh - TLSH:
T1FF39E0F3528BEE8C398A8B43A8E711447046D74C702297644A88772DC5BC7FD6E60AB1 - Submitted as: 87688224360.pdf
- File type: pdf · Size: 91423 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=67+mustang+restoration+guide, http://files.gasperandassociates.com/uploads/1/3/0/9/130969079/wabometiper.pdf, http://files.jmancastudios.com/uploads/1/3/2/7/132712043/a76d13cfb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=67+mustang+restoration+guide
- http://files.gasperandassociates.com/uploads/1/3/0/9/130969079/wabometiper.pdf
- http://files.jmancastudios.com/uploads/1/3/2/7/132712043/a76d13cfb.pdf
- http://zuziwuf.yt8music.com/uploads/1/3/1/3/131381761/49fe66aa5f081.pdf
- http://nufogod.drderickclinic.com/uploads/1/3/1/4/131454106/jexogi-mavavol-gavipezep-kurovafafove.pdf
- https://uploads.strikinglycdn.com/files/566e536e-82e4-4384-8b60-cc2816f12c77/zoninabufegoji.pdf
- https://uploads.strikinglycdn.com/files/4ad06d0d-b253-4a1e-bd06-4d65d5d3af43/19247214208.pdf
- https://uploads.strikinglycdn.com/files/b441d077-1ff1-4139-ac88-8f6025879458/witukedexip.pdf
- https://uploads.strikinglycdn.com/files/21ae8488-06c0-4c72-b9f1-727f086b4cd8/82846481754.pdf
- http://files.walkerabel.com/uploads/1/3/1/8/131857193/wemefosul-rikilelup.pdf
- http://palefuku.goldenwhitesretrievers.com/uploads/1/3/1/4/131406211/4815478.pdf
- https://site-1036724.mozfiles.com/files/1036724/boziw.pdf
- https://site-1038837.mozfiles.com/files/1038837/kuxorelukosisomexabax.pdf
- https://site-1036850.mozfiles.com/files/1036850/dojolagolukikepuruxus.pdf
- https://site-1040000.mozfiles.com/files/1040000/72264683266.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.gasperandassociates.com
- files.jmancastudios.com
- zuziwuf.yt8music.com
- nufogod.drderickclinic.com
- uploads.strikinglycdn.com
- files.walkerabel.com
- palefuku.goldenwhitesretrievers.com
- site-1036724.mozfiles.com
- site-1038837.mozfiles.com
- site-1036850.mozfiles.com
- site-1040000.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report