SUSPICIOUS — 8792242.pdf
SUSPICIOUS — 8792242.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
90a89b0d39b16a52c336724fc2539dbe804a3c23376a7b14f11fa99cac4f2e65 - SHA-1:
7f5506b8bcba8b08dea059300c056e7fc71028c3 - MD5:
82b801c1b9d9827a73f85799ee483571 - ssdeep:
768:KgGzpDhpVqEDAWioqZnI6RwUrDl/2dbb1HAoVMTpLo+6C1L3II7R+EO51Py1n550:XGFNpVq0Kledyoe0kL3II7QEmVy1LKUy - TLSH:
T139328DF754ABED8C7A8BAB4768F721651989C38861369B30048C776CC4BC5BE7F50920 - Submitted as: 8792242.pdf
- File type: pdf · Size: 46285 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=dave%20ramsey%20financial%20peace%20book%20pdf, https://cdn.shopify.com/s/files/1/0495/7208/5926/files/61869588445.pdf, https://cdn.shopify.com/s/files/1/0483/5757/2761/files/the_ruby_slipper_caf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=dave%20ramsey%20financial%20peace%20book%20pdf
- https://cdn.shopify.com/s/files/1/0495/7208/5926/files/61869588445.pdf
- https://cdn.shopify.com/s/files/1/0483/5757/2761/files/the_ruby_slipper_caf.pdf
- https://cdn.shopify.com/s/files/1/0433/8050/6773/files/fekizepeworovisujugujepi.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/44174335733.pdf
- https://cdn.shopify.com/s/files/1/0266/7967/3011/files/adobe_reader_cracked_windows_10.pdf
- https://cdn.shopify.com/s/files/1/0268/6717/1508/files/gully_cricket_apk_pro.pdf
- https://cdn.shopify.com/s/files/1/0428/7299/5996/files/dozosukisolawib.pdf
- https://uploads.strikinglycdn.com/files/eb7c500b-8cab-4ea4-a4ff-525f9810a43c/tumusugomumazozo.pdf
- https://uploads.strikinglycdn.com/files/bbf65025-7d1c-4a62-a48d-8752624ddc6c/55137996681.pdf
- https://uploads.strikinglycdn.com/files/56358574-aa92-4681-ae9d-9ca328b120d7/kojewaziwulepebido.pdf
- https://uploads.strikinglycdn.com/files/98042ebc-a589-4f79-a4ec-0bd72c90e340/33440171497.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8a9314d7889.pdf
- https://cdn-cms.f-static.net/uploads/4377912/normal_5f8b2dfaaa411.pdf
- https://cdn-cms.f-static.net/uploads/4379380/normal_5f8ba5c348ad4.pdf
- https://cdn-cms.f-static.net/uploads/4369318/normal_5f8a7de30faf9.pdf
- https://uploads.strikinglycdn.com/files/221d0524-b89c-4ced-879b-a9e2d3ca5426/milivotinojofuredol.pdf
- https://uploads.strikinglycdn.com/files/40c673ea-599f-4ceb-a7ab-ff1234f592ee/77513542904.pdf
- https://uploads.strikinglycdn.com/files/2c7d63be-94f9-477a-ac50-d0f0fbef8280/diruxumidowapufobolobabag.pdf
- https://uploads.strikinglycdn.com/files/485683ff-5919-4929-b60f-e2e7b6bae9dc/propresenter_training_manual.pdf
- https://s3.amazonaws.com/leguvefu/3255981940.pdf
- https://s3.amazonaws.com/fasanag/ashanti_golden_stool.pdf
- https://s3.amazonaws.com/felasorarabipis/benedictine_rule.pdf
- https://s3.amazonaws.com/xanebavifamopez/gonasiforimazavevutodijij.pdf
- https://s3.amazonaws.com/felasorarabipis/physics_equations_of_motion.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report