SUSPICIOUS — internetsiz_oyun_indirme_program_indir.pdf
SUSPICIOUS — internetsiz_oyun_indirme_program_indir.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
770914314beb24204d7caf6169ca0c4ace28f0274aaf106e3527a34399d0f2e4 - SHA-1:
478f2de5247a5fb72d67c28a46761a402fab01b1 - MD5:
c82eb4498379eda6e676165bb41deba3 - ssdeep:
3072:XFTp+ums9Hl3ttDVai8tf7t2jpyPpdIsP0Ate7dj5C9HUJbqKocMkLInUH/uKnj:11+umsP3ttRaimIpoHOB5CBUJbqrauk - TLSH:
T1763FADA21497CDF96F8A67D364B2F78C5139BD882521F57004D8E968812C6BF2E0DE31 - Submitted as: internetsiz_oyun_indirme_program_indir.pdf
- File type: pdf · Size: 159857 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=internetsiz+oyun+indirme+program%25C4%25B1+indir, https://uploads.strikinglycdn.com/files/3d9bdc03-0c28-4085-a373-56b278dab524/45356056375.pdf, https://uploads.strikinglycdn.com/files/f13691f9-6fd8-4e4f-93b2-5329d2bbfe34/kuwulavuximeb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=internetsiz+oyun+indirme+program%25C4%25B1+indir
- https://uploads.strikinglycdn.com/files/3d9bdc03-0c28-4085-a373-56b278dab524/45356056375.pdf
- https://uploads.strikinglycdn.com/files/f13691f9-6fd8-4e4f-93b2-5329d2bbfe34/kuwulavuximeb.pdf
- https://uploads.strikinglycdn.com/files/aae95163-1fc1-4e17-bb33-ac3caeab8f73/52913165728.pdf
- https://uploads.strikinglycdn.com/files/34f75860-466b-454c-92ee-0500a8cb88cf/59556284327.pdf
- https://siregudak.weebly.com/uploads/1/3/0/7/130738759/8683090.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/2a0b0974630.pdf
- https://cdn.shopify.com/s/files/1/0431/6551/5933/files/lay_it_on_the_line_tab.pdf
- https://cdn.shopify.com/s/files/1/0432/0110/1984/files/bowflex_power_pro_workout_video.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/volvamos_a_la_fuente.pdf
- https://cdn-cms.f-static.net/uploads/4379731/normal_5f8f83e038893.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f8fdbaebe939.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f8711718b334.pdf
- https://uploads.strikinglycdn.com/files/b7c08134-6175-4124-9145-4decb5959958/42114594501.pdf
- https://uploads.strikinglycdn.com/files/27e73ccb-45a2-4ae8-9dff-d36159782c77/makikimu.pdf
- https://uploads.strikinglycdn.com/files/3401efa8-f128-4a7a-b456-bbf91c1ace36/16878681648.pdf
- https://uploads.strikinglycdn.com/files/4d91f4e1-1988-4918-8195-ae4d6f4b66d8/lidit.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/zajefux-lulibowaban-wofusu-domunewitug.pdf
- https://lotagixowila.weebly.com/uploads/1/3/1/1/131164100/fexizidumod.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- siregudak.weebly.com
- zimiduninu.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- riragojefo.weebly.com
- lotagixowila.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report