SUSPICIOUS — 3517082298.pdf
SUSPICIOUS — 3517082298.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7ef7fe0f42fa938a97cd1a612b85df53a3931198eda606ee6ddce67b45d0f793 - SHA-1:
0a5e695f6524660935b7871f908d07355d8e43ad - MD5:
aa1e40e5312667ec9b1be24211e0e3a6 - ssdeep:
768:FgGzpD9IWZBLFJhHT09dO0cFVcyhZP5XTAxqVd5bhT7H+nTqAdOh7s1HxsL:WGFhjZdFjzQdO0+Vzh3XxVd5bkTHas1e - TLSH:
T11233B0F390A7DC4C6586DB4399E50066B05AE7C96123C7B818D97BBCC0BC2FDAD50A60 - Submitted as: 3517082298.pdf
- File type: pdf · Size: 48517 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=numberformatter+remove+currency+symbol, https://site-1040286.mozfiles.com/files/1040286/88327468461.pdf, https://site-1042504.mozfiles.com/files/1042504/savusure.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=numberformatter+remove+currency+symbol
- https://site-1040286.mozfiles.com/files/1040286/88327468461.pdf
- https://site-1042504.mozfiles.com/files/1042504/savusure.pdf
- https://site-1044152.mozfiles.com/files/1044152/fabexeremugogozuzoso.pdf
- https://site-1040668.mozfiles.com/files/1040668/webogozipak.pdf
- http://files.johncochranartwork.com/uploads/1/3/0/8/130874161/0595eb99e55.pdf
- http://files.cmgaesthetics.com/uploads/1/3/1/4/131454899/nupakazowe_gelubuturamos_kufose_kenonevovekiw.pdf
- http://mirat.thejunkmanadv.com/uploads/1/3/2/8/132815004/8138044.pdf
- http://files.johnashcroftandcompany.com/uploads/1/3/0/8/130814009/pelaxiwuroxolosi.pdf
- http://files.darkshadowenterprise.com.au/uploads/1/3/2/7/132740541/8e3cfbdce50.pdf
- http://files.nod-production.de/uploads/1/3/0/7/130776118/3864674.pdf
- https://uploads.strikinglycdn.com/files/f3ba9444-9fc1-47a2-b071-565db937fc98/30595746373.pdf
- https://uploads.strikinglycdn.com/files/464cf51d-610b-4c36-b268-6143a5a77553/95656511671.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1040286.mozfiles.com
- site-1042504.mozfiles.com
- site-1044152.mozfiles.com
- site-1040668.mozfiles.com
- files.johncochranartwork.com
- files.cmgaesthetics.com
- mirat.thejunkmanadv.com
- files.johnashcroftandcompany.com
- files.darkshadowenterprise.com.au
- files.nod-production.de
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report