SUSPICIOUS — 9761924.pdf
SUSPICIOUS — 9761924.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7273890978a612075f5f77d2c107d266822cfbfd5eb14501cf81589068bcbc95 - SHA-1:
0d12a8fde0b7dc9d47c61e88959b3e0018dcf6fa - MD5:
725e0c855fbb33f9b6a2abec4abe05fd - ssdeep:
768:dgGzpDNpwqPXsftDDJBQcePPETlvEKL0uu2EMzm3pDz7Dt0vzn+CGH5:eGFZpdEJsKwV9pDz7Gvzn+CGH5 - TLSH:
T12E328DF310A7EE4C7E8B9B43ADA614996099D38DB17693A04588772CC47C6BDBF10860 - Submitted as: 9761924.pdf
- File type: pdf · Size: 45852 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=definicion%20de%20creatividad%20e%20innovacion, https://site-1039490.mozfiles.com/files/1039490/lupazobeb.pdf, https://site-1041501.mozfiles.com/files/1041501/lusodijuzogidotiliwepiz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=definicion%20de%20creatividad%20e%20innovacion
- https://site-1039490.mozfiles.com/files/1039490/lupazobeb.pdf
- https://site-1041501.mozfiles.com/files/1041501/lusodijuzogidotiliwepiz.pdf
- https://site-1041378.mozfiles.com/files/1041378/banijugeleketej.pdf
- https://site-1038777.mozfiles.com/files/1038777/bobekawawip.pdf
- https://site-1038488.mozfiles.com/files/1038488/38151490731.pdf
- https://uploads.strikinglycdn.com/files/169ae1cc-a10f-4ac9-92af-e47b18c3e47f/tunori.pdf
- https://uploads.strikinglycdn.com/files/14d55eab-ce88-4b21-a1b2-765c1694d5a7/tesexawurezaju.pdf
- https://uploads.strikinglycdn.com/files/32701434-af0e-4545-9112-b6ef4f4561f8/zamiz.pdf
- https://uploads.strikinglycdn.com/files/4bf85e83-dced-4b3f-b64e-0506e505f0c8/55529154465.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f88034be75b3.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f8839001472e.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f88425c71000.pdf
- https://cdn-cms.f-static.net/uploads/4371013/normal_5f8874ab878a6.pdf
- https://cdn-cms.f-static.net/uploads/4371023/normal_5f8836a4c1999.pdf
- https://cdn.shopify.com/s/files/1/0429/8758/5699/files/nurej.pdf
- https://cdn.shopify.com/s/files/1/0430/6803/1143/files/61236553935.pdf
- https://jobubati.weebly.com/uploads/1/3/1/4/131453688/xujoromo.pdf
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/jusubeveje.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/bagatazojiz_sidatasofugugor_sofaxazute_gureluf.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/2a5b38eef3430.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/jaxisi.pdf
- https://site-1043601.mozfiles.com/files/1043601/47944507587.pdf
- https://site-1043037.mozfiles.com/files/1043037/17646926932.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- site-1039490.mozfiles.com
- site-1041501.mozfiles.com
- site-1041378.mozfiles.com
- site-1038777.mozfiles.com
- site-1038488.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- jobubati.weebly.com
- vixijusodu.weebly.com
- genigudepa.weebly.com
- guwomenod.weebly.com
- mojivimimujovo.weebly.com
- site-1043601.mozfiles.com
- site-1043037.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report