SUSPICIOUS — 17700315712.pdf
SUSPICIOUS — 17700315712.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7c70556e89aac2aaa8d01d632a0289466bad6cd1277f2e2aeb429ae8d4e0e50a - SHA-1:
a4bc9185816cd499cda02221b1c77dd847c09a6d - MD5:
c82016f3c1768d5b60c52276010357df - ssdeep:
768:hgGzpDufyjLaNKlJUDf+1vvk2JqsB7E9RdDIcwEC2puc4Y3:SGF6dIvM2bsLIcwEC2puc4Y3 - TLSH:
T17A319DF30097ED8C3683AB07ADAA24995146CB8C7137EBA04888327CE57C6BD7D15961 - Submitted as: 17700315712.pdf
- File type: pdf · Size: 40886 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=changing+pdf+to+word+online, https://cdn.shopify.com/s/files/1/0434/1448/7190/files/segonolubefitemo.pdf, https://cdn.shopify.com/s/files/1/0443/6181/0076/files/ninova.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=changing+pdf+to+word+online
- https://cdn.shopify.com/s/files/1/0434/1448/7190/files/segonolubefitemo.pdf
- https://cdn.shopify.com/s/files/1/0443/6181/0076/files/ninova.pdf
- https://cdn.shopify.com/s/files/1/0428/8148/2919/files/48082890330.pdf
- https://cdn.shopify.com/s/files/1/0434/3663/8360/files/forbidden_woods_map_bloodborne.pdf
- https://uploads.strikinglycdn.com/files/4be0566e-b935-44ca-9174-f6fb173e383b/vapegekizakiregimabota.pdf
- https://uploads.strikinglycdn.com/files/68042879-deac-4d27-bbda-4e91dc91fec2/18453860309.pdf
- https://uploads.strikinglycdn.com/files/666021ca-476a-473b-a2e7-74e223796bf8/54008737010.pdf
- https://cdn.shopify.com/s/files/1/0433/1778/8830/files/91342660779.pdf
- https://cdn.shopify.com/s/files/1/0433/5943/6951/files/femojolata.pdf
- https://cdn.shopify.com/s/files/1/0469/4612/3937/files/h_l_college_full_form.pdf
- https://cdn.shopify.com/s/files/1/0432/9901/2766/files/malaria_parasite.pdf
- http://karepe.nltcassville.org/uploads/1/3/1/1/131164250/4750852.pdf
- http://files.freemanschwabe.com/uploads/1/3/2/6/132681658/watiniroxipi.pdf
- http://jejabovik.mirembegirlsvocationalcentre.com/uploads/1/3/1/0/131070450/zubapowiramivo_nawurogirekam_vuwemiwiwebelak_pekilogidanezi.pdf
- http://files.skybluemusic.org/uploads/1/3/1/4/131409755/4521261.pdf
- http://files.lifelinegospelministries.org/uploads/1/3/0/7/130739678/731b6a9f3fe02a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- karepe.nltcassville.org
- files.freemanschwabe.com
- jejabovik.mirembegirlsvocationalcentre.com
- files.skybluemusic.org
- files.lifelinegospelministries.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report