SUSPICIOUS — 4604693.pdf
SUSPICIOUS — 4604693.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
7f805f430391607f45c82f3f6cf3df6cfff75a28ab29b8eb7e3638b267fc031c - SHA-1:
3ce62dd7bfedb81785500250d79eea5659ad5b30 - MD5:
0934d5bb379be65a1181b3b7fffe2db7 - ssdeep:
768:6gGzpDi4tpfkNwKK3jYwWBeizKlLD6cXLK:nGFeqMNpYiel/6cXLK - TLSH:
T1E2328EF310A7DD8CBE8A9F079AAB045D615EC7482127977009C87B6CC4BC6FD2E10661 - Submitted as: 4604693.pdf
- File type: pdf · Size: 43434 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=mp4%20movies%20download%202019, https://uploads.strikinglycdn.com/files/6611945e-b7e4-4ced-96c4-572e7f123ced/84401028325.pdf, https://uploads.strikinglycdn.com/files/e610907a-bcf6-4b66-8a98-18d18d69ca9b/dejamusazobinutap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=mp4%20movies%20download%202019
- https://uploads.strikinglycdn.com/files/6611945e-b7e4-4ced-96c4-572e7f123ced/84401028325.pdf
- https://uploads.strikinglycdn.com/files/e610907a-bcf6-4b66-8a98-18d18d69ca9b/dejamusazobinutap.pdf
- https://cdn-cms.f-static.net/uploads/4412181/normal_5f95c7e0186b6.pdf
- https://uploads.strikinglycdn.com/files/9765d325-e6f3-4a80-a86a-8f5be084b198/texas_conservative_voter_guide_2019.pdf
- https://kebupud.files.wordpress.com/2020/11/16674380217.pdf
- https://uploads.strikinglycdn.com/files/c6f70b0f-2f12-4a08-8f29-20389367dd62/70976123327.pdf
- https://pozeduribo.files.wordpress.com/2020/11/44755657443.pdf
- https://taruzabob.weebly.com/uploads/1/3/4/4/134493447/jujomov.pdf
- https://uploads.strikinglycdn.com/files/d748ca6b-bfff-45b2-bba1-f4d199b897c2/golaletex.pdf
- https://mukawikakava.files.wordpress.com/2020/11/a_course_in_miracles_workbook.pdf
- https://uploads.strikinglycdn.com/files/5699e873-f076-45c8-9722-be6b4a881abe/60372123722.pdf
- https://uploads.strikinglycdn.com/files/bf2255f5-d716-4c31-b282-dcbe9b7aa79e/diwuvetalurinewokageka.pdf
- https://uploads.strikinglycdn.com/files/68fe698f-83a8-4725-ad27-b640ed84831b/35467636806.pdf
- https://uploads.strikinglycdn.com/files/f64d919d-9880-43c4-912f-e334c0a830a2/66876250473.pdf
- https://uploads.strikinglycdn.com/files/46e4658c-5e12-4e3f-93b6-9aea489fb2dd/luke_chapter_14_summary.pdf
- https://wusatotaluvak.weebly.com/uploads/1/3/4/4/134469206/mokezebobe-rudaz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- kebupud.files.wordpress.com
- pozeduribo.files.wordpress.com
- taruzabob.weebly.com
- mukawikakava.files.wordpress.com
- wusatotaluvak.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report