SUSPICIOUS — 25108183700.pdf
SUSPICIOUS — 25108183700.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7d1829de517818907c246539ff7ca8a57db08b0d0def88aef1ba67df866b2a34 - SHA-1:
82ff06ef59de6504d1acae330609c7d6aea106e8 - MD5:
13d0bbb8d7e8f1f7d2639e74e8af624c - ssdeep:
768:2gGzpDMkApuVz/Vba8b6PJ4bTb5xlMPjm0boR04DIMx9:jGFQW04NxWbmeoRVDIMx9 - TLSH:
T1772F6DF341E7ED8C7A4E6B136EEA108D5149D24D6122A7A4458C776CD0BC5FCBF00A61 - Submitted as: 25108183700.pdf
- File type: pdf · Size: 35330 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=velamma+pdf+free+download, https://site-1039847.mozfiles.com/files/1039847/buposuzewelavifeti.pdf, https://site-1037026.mozfiles.com/files/1037026/fexitisata.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=velamma+pdf+free+download
- https://site-1039847.mozfiles.com/files/1039847/buposuzewelavifeti.pdf
- https://site-1037026.mozfiles.com/files/1037026/fexitisata.pdf
- https://site-1036929.mozfiles.com/files/1036929/11272177953.pdf
- https://site-1038844.mozfiles.com/files/1038844/sebezumisawixoxelubuxin.pdf
- https://site-1036698.mozfiles.com/files/1036698/vetinesexanifowunu.pdf
- https://cdn.shopify.com/s/files/1/0431/0528/8352/files/logo_modernism_ju_design.pdf
- https://cdn.shopify.com/s/files/1/0432/3940/7784/files/fuvukufavudenitakagen.pdf
- https://cdn.shopify.com/s/files/1/0477/5165/9676/files/21781889293.pdf
- https://cdn.shopify.com/s/files/1/0484/2877/7630/files/sum_of_cubes_definition.pdf
- https://cdn.shopify.com/s/files/1/0463/0380/5600/files/vivitibilajozoxesan.pdf
- https://uploads.strikinglycdn.com/files/db8dba7b-a7b3-433f-8d5d-e2aa743d1f03/mujimojepesisuvimejazelo.pdf
- https://uploads.strikinglycdn.com/files/865e56c5-3b5b-48c7-88d4-8c50bf977318/13082331263.pdf
- https://uploads.strikinglycdn.com/files/05002934-622b-4432-9bfe-ce9f72ddd709/99274767505.pdf
- https://uploads.strikinglycdn.com/files/7fa00d03-9955-4c3f-9ff3-3cf0d7daea1e/57559361233.pdf
- https://cdn.shopify.com/s/files/1/0483/0163/7794/files/ak_47_sight_radius.pdf
- https://cdn.shopify.com/s/files/1/0434/2516/9565/files/social_network_script_codecanyon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1039847.mozfiles.com
- site-1037026.mozfiles.com
- site-1036929.mozfiles.com
- site-1038844.mozfiles.com
- site-1036698.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report