SUSPICIOUS — 0266a73d46.pdf
SUSPICIOUS — 0266a73d46.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7679ea7804890d746e89b6045e506e255d9f7a6b2bdaadcb7bdfb3383fe83294 - SHA-1:
b6ab7bb23e670a0cac24cbbca1428ef895af939f - MD5:
30c668d6786e6eacb683142b9a5e202b - ssdeep:
1536:nGF/pEE4Hj0AtEa3HnuPji9MoBqa7w0VQ:GF/pEEm0XiHnuPCMoyx - TLSH:
T1C735AEF304ABED4C7B8B2F039DF61259614AD38961329B50044C7B2DE57CABE6F20651 - Submitted as: 0266a73d46.pdf
- File type: pdf · Size: 61327 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=dnd%205e%20weapon%20bond, https://uploads.strikinglycdn.com/files/b27cecfc-b7ed-4f5e-994d-a4672ce83e7e/tamotewotibitapojukul.pdf, https://uploads.strikinglycdn.com/files/451c619c-9c76-4577-99a9-2b57e7ec2da2/93166558534.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=dnd%205e%20weapon%20bond
- https://uploads.strikinglycdn.com/files/b27cecfc-b7ed-4f5e-994d-a4672ce83e7e/tamotewotibitapojukul.pdf
- https://uploads.strikinglycdn.com/files/451c619c-9c76-4577-99a9-2b57e7ec2da2/93166558534.pdf
- https://uploads.strikinglycdn.com/files/c282d013-3862-43a3-9c22-f8c4fb451050/19597677789.pdf
- https://uploads.strikinglycdn.com/files/12aaf8c1-379f-4a5b-aa03-0ff808d96c56/rugudukimanenakuxuzugivuk.pdf
- https://uploads.strikinglycdn.com/files/f0f47ce6-0e80-497d-9749-66b73f26fb03/sisaleripiv.pdf
- https://cdn.shopify.com/s/files/1/0499/8214/4675/files/mimajagefefigigogukav.pdf
- https://cdn.shopify.com/s/files/1/0486/4632/4382/files/ecco_guidelines_ulcerative_colitis_management.pdf
- https://cdn.shopify.com/s/files/1/0482/9872/1442/files/2007_dodge_avenger_specs.pdf
- https://cdn-cms.f-static.net/uploads/4367665/normal_5f875945627b2.pdf
- https://cdn-cms.f-static.net/uploads/4368996/normal_5f87ed1d7d9fa.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f87333f05a83.pdf
- https://cdn-cms.f-static.net/uploads/4369777/normal_5f88103cafc11.pdf
- https://cdn.shopify.com/s/files/1/0501/0246/8765/files/lefenemikixikazove.pdf
- https://cdn.shopify.com/s/files/1/0433/5144/1560/files/el_poder_del_santo_nombre_de_jesus.pdf
- https://cdn.shopify.com/s/files/1/0430/7527/2855/files/atom_drop_through_longboard_36_inch.pdf
- https://uploads.strikinglycdn.com/files/aecf17fb-4372-4bd0-91c7-3b08c8f9b744/36450092873.pdf
- https://uploads.strikinglycdn.com/files/de4e96ef-12d0-43bc-ad59-1c2820d78b30/rozudanosufubutofewux.pdf
- https://uploads.strikinglycdn.com/files/28123892-8491-4a37-a003-b741a56cc4e9/bewapidub.pdf
- https://uploads.strikinglycdn.com/files/02aec9e1-d257-41fa-8306-27229ac62a1a/15845732985.pdf
- https://site-1038614.mozfiles.com/files/1038614/79672155536.pdf
- https://site-1040101.mozfiles.com/files/1040101/rajatenodawububepos.pdf
- https://site-1044012.mozfiles.com/files/1044012/35607971091.pdf
- https://site-1036803.mozfiles.com/files/1036803/35603564133.pdf
- https://site-1039576.mozfiles.com/files/1039576/1868174383.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1038614.mozfiles.com
- site-1040101.mozfiles.com
- site-1044012.mozfiles.com
- site-1036803.mozfiles.com
- site-1039576.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report