SUSPICIOUS — 22232557864.pdf
SUSPICIOUS — 22232557864.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
87c2cf99ba0e3dd6847a30e311f7c462b33d17baa1b18aea41c8f43c98fe06a5 - SHA-1:
1aeb4245b44ff412839c3016d5695bb252e5a63a - MD5:
cde97fba38960ecc625bf85953a2567c - ssdeep:
1536:iGFqtQYbyWVPZqkO9ppKYWEsp9J0Xuo8CWwiQ5O9:bFqtueI1pdW5pX0XtnBi/ - TLSH:
T12935AFF3515BED8C7A8B6F4759AB0958604AD6893132AB9005CCB72CC87C6BE7F01950 - Submitted as: 22232557864.pdf
- File type: pdf · Size: 62100 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=abecedario+coreano+espa%25C3%25B1ol+pdf, https://uploads.strikinglycdn.com/files/67d6bbc2-6064-428e-ba58-e5c8d2baf4ec/jezuviz.pdf, https://uploads.strikinglycdn.com/files/dca48ac0-4bbe-4b5c-88eb-f80d48772fe5/denekiruz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=abecedario+coreano+espa%25C3%25B1ol+pdf
- https://uploads.strikinglycdn.com/files/67d6bbc2-6064-428e-ba58-e5c8d2baf4ec/jezuviz.pdf
- https://uploads.strikinglycdn.com/files/dca48ac0-4bbe-4b5c-88eb-f80d48772fe5/denekiruz.pdf
- https://uploads.strikinglycdn.com/files/5b88a8bd-a35f-46a1-9e3f-4bfea0875046/gefozikitexotisok.pdf
- https://site-1036864.mozfiles.com/files/1036864/rimidisogami.pdf
- https://site-1037069.mozfiles.com/files/1037069/zexiwixigufusa.pdf
- https://site-1041770.mozfiles.com/files/1041770/tolesatatideropi.pdf
- https://site-1036805.mozfiles.com/files/1036805/61752211513.pdf
- https://uploads.strikinglycdn.com/files/4e7cb53d-6c56-4528-b528-ffa9c6a7dcf7/bitovaxu.pdf
- https://uploads.strikinglycdn.com/files/d91a1dad-6c5e-42a0-b31c-e1fe03fd9375/wadute.pdf
- https://uploads.strikinglycdn.com/files/a3630240-2570-44a5-9e0f-3fccbbd99b0c/19723548916.pdf
- https://uploads.strikinglycdn.com/files/449bff61-cd8f-4401-8d39-55bcc5b51e50/mugadovigopozitotozajevu.pdf
- https://uploads.strikinglycdn.com/files/0cce6ebb-7269-4979-a3f4-cde259fd5bc5/powosu.pdf
- https://uploads.strikinglycdn.com/files/b8a7f3ce-a178-4b29-bf86-84dc3b1d2160/livijik.pdf
- https://uploads.strikinglycdn.com/files/2dfb3e05-2863-4a83-8718-6197ef542c33/lovuj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036864.mozfiles.com
- site-1037069.mozfiles.com
- site-1041770.mozfiles.com
- site-1036805.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report