SUSPICIOUS — 8984039.pdf
SUSPICIOUS — 8984039.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8e4455ab630afb75d47eb2cfd2e7de825da19cf76305fafc9f7c3399141bf41a - SHA-1:
1aa9de5dd8d652c183c510459d3cd9eada53f9b7 - MD5:
7cade31d45d3e0a9da30332eb9b517b4 - ssdeep:
768:xgGzpDpeXpaZLcvNXwLrZdckOMn5XQL6KHA9uPF4h5aM+Vk2PYKK:CGF9eZm/5XcSuPw5T+m4K - TLSH:
T186337CF31097ED8C778BAB53AEE7005C608AC789A2229B50548C7B1CC5BC6FD7E11661 - Submitted as: 8984039.pdf
- File type: pdf · Size: 48635 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=download%20riverdale%20full%20season%201%20720, https://uploads.strikinglycdn.com/files/bf45d737-1df3-474b-9cdb-0f3ad7a85ee4/polexamizekejumuxavakokog.pdf, https://uploads.strikinglycdn.com/files/04060e2b-9604-4a66-91e2-c9b922e9550a/libekeguxux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=download%20riverdale%20full%20season%201%20720
- https://uploads.strikinglycdn.com/files/bf45d737-1df3-474b-9cdb-0f3ad7a85ee4/polexamizekejumuxavakokog.pdf
- https://uploads.strikinglycdn.com/files/04060e2b-9604-4a66-91e2-c9b922e9550a/libekeguxux.pdf
- https://uploads.strikinglycdn.com/files/0015aa25-ee58-47c5-840c-52df047769b2/91051714559.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f871998e013e.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f870603b7b1f.pdf
- https://cdn-cms.f-static.net/uploads/4366305/normal_5f8731d9b5bb6.pdf
- https://cdn-cms.f-static.net/uploads/4366622/normal_5f872b4156026.pdf
- https://cdn.shopify.com/s/files/1/0502/8410/1804/files/turkish_march_piano_sheet_music_free.pdf
- https://cdn.shopify.com/s/files/1/0496/4948/3939/files/miata_roll_bar_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0496/2730/0036/files/exantema_sbito_o_sexta_enfermedad.pdf
- https://cdn.shopify.com/s/files/1/0266/8557/1260/files/94640953420.pdf
- https://cdn.shopify.com/s/files/1/0437/3122/2682/files/vejut.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/9836671.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/pabagugiridepoluwaru.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/linurigaruxox.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bewoti.pdf
- https://site-1044055.mozfiles.com/files/1044055/getugifekekazofakaleg.pdf
- https://site-1040509.mozfiles.com/files/1040509/5394673226.pdf
- https://site-1040002.mozfiles.com/files/1040002/sopuzed.pdf
- https://site-1048491.mozfiles.com/files/1048491/pirukijozunek.pdf
- https://cdn-cms.f-static.net/uploads/4366304/normal_5f8730fc8c5ea.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f86f660dc18f.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f8708e0d4d02.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f8708ced05e3.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- jufaxexave.weebly.com
- xojerajap.weebly.com
- fijojonibiw.weebly.com
- vuxozajuje.weebly.com
- site-1044055.mozfiles.com
- site-1040509.mozfiles.com
- site-1040002.mozfiles.com
- site-1048491.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report