SUSPICIOUS — 2969610.pdf
SUSPICIOUS — 2969610.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
8724d848d3654b5848c6b1d5d31560e78e0211402e68f5cbe565ebddaed6f032 - SHA-1:
3d80151649d17eacaf47f2da4698b10af9f3169b - MD5:
582ae06d013891ebc2bf157cc47839c6 - ssdeep:
768:cgGzpD1HYYcBKc6Cdlq8V6Ra1YgpCWicFwOly34qADwiPwWBe0khXnwOR7:5GFRHVRa1Ygprzwky/AD/PwWBBkdwOR7 - TLSH:
T11E327DF71097EC8C7B8FAF03EDAB1159918AD3892033A6500588776DC1BCABD7E10965 - Submitted as: 2969610.pdf
- File type: pdf · Size: 44695 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=joint%20and%20combined%20variation%20worksheet%20doc, https://cdn.shopify.com/s/files/1/0434/2421/9288/files/crop_pages_in.pdf, https://cdn.shopify.com/s/files/1/0432/5697/1432/files/to_kill_a_mockingbird_packet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=joint%20and%20combined%20variation%20worksheet%20doc
- https://cdn.shopify.com/s/files/1/0434/2421/9288/files/crop_pages_in.pdf
- https://cdn.shopify.com/s/files/1/0432/5697/1432/files/to_kill_a_mockingbird_packet.pdf
- https://cdn.shopify.com/s/files/1/0433/9400/7191/files/89995633329.pdf
- https://cdn.shopify.com/s/files/1/0266/8360/5185/files/android_textview_multiline_truncate.pdf
- https://cdn.shopify.com/s/files/1/0481/8717/9160/files/face_negotiation_theory_examples_in_movies.pdf
- https://uploads.strikinglycdn.com/files/f5c0dc23-58a1-4bb8-baa4-b942d8ba955b/fowowafabojirawadalo.pdf
- https://uploads.strikinglycdn.com/files/047b891e-13ad-4985-b87d-e81aeff0daaa/pemixidi.pdf
- https://uploads.strikinglycdn.com/files/83c74727-effe-44bb-9a39-e81de6d13463/54928694574.pdf
- https://uploads.strikinglycdn.com/files/38e6c22a-c23d-45b1-ab30-995901087fa2/36446865292.pdf
- https://cdn.shopify.com/s/files/1/0434/1887/8104/files/vogegofojujemidelazutiput.pdf
- https://cdn.shopify.com/s/files/1/0483/5940/7765/files/73755299440.pdf
- https://cdn.shopify.com/s/files/1/0437/0799/0184/files/prefixes_worksheets_for_grade_2.pdf
- https://cdn.shopify.com/s/files/1/0494/3288/7463/files/8494300345.pdf
- https://cdn.shopify.com/s/files/1/0491/9364/8294/files/analytic_geometry_reviewer.pdf
- https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/c9440356.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/3966742.pdf
- https://uploads.strikinglycdn.com/files/bef0c953-8226-4051-b64b-455559e5fb1d/gofepo.pdf
- https://uploads.strikinglycdn.com/files/3db39247-a0c9-454e-a3a5-135c10fa9d89/nemavizojupetuzukev.pdf
- https://uploads.strikinglycdn.com/files/9b36e304-425b-4e3e-8eb9-785091837706/pigobuvemodekenuduxolo.pdf
- https://uploads.strikinglycdn.com/files/813aca47-14fa-46b3-891f-687bdeb3bfb9/29559756533.pdf
- https://uploads.strikinglycdn.com/files/d147d6b2-b173-4123-be98-437fad57b37d/bowikagapanefifenozi.pdf
- https://uploads.strikinglycdn.com/files/b8a73c1d-cb44-4a55-b226-6cb44970e4d1/support.nintendo.com_wii_error_code_51030.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- rabugotekinevod.weebly.com
- pigogokeda.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report