SUSPICIOUS — degadavera.pdf
SUSPICIOUS — degadavera.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9238138bcc453a115e352a7bbf15727fa6411b001fddf1df3f3a2ceb5578a8c3 - SHA-1:
cbce8737f3543315ab17e7a137182c81dfb8ecc6 - MD5:
4004fd7d524f9c0e7f0fa059f9518622 - ssdeep:
768:fgGzpDPvHB0ngMHohB+FCQJ1E5QC61olNap6wkUg6Jbc77A:oGFzvH0gAw+YqLolMpLkUg6Jbc77A - TLSH:
T11132AFF35167FD8C7987AB139EA71588518AC38C613293A0458C772DC0BC9FD7E54AA0 - Submitted as: degadavera.pdf
- File type: pdf · Size: 44358 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=chemical+properties+of+hydrogen+pdf, https://uploads.strikinglycdn.com/files/54f74765-ef9b-411e-a9ed-56bf1ae7bc05/zuvamisikatotufebuxebafuf.pdf, https://uploads.strikinglycdn.com/files/6d105b35-7c26-4750-a017-5da75a557670/zipamexiririrekaketaro.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=chemical+properties+of+hydrogen+pdf
- https://uploads.strikinglycdn.com/files/54f74765-ef9b-411e-a9ed-56bf1ae7bc05/zuvamisikatotufebuxebafuf.pdf
- https://uploads.strikinglycdn.com/files/6d105b35-7c26-4750-a017-5da75a557670/zipamexiririrekaketaro.pdf
- https://uploads.strikinglycdn.com/files/3eacfe1a-0eac-4891-b0f3-58c9db69d64a/ravasokunofafufasaw.pdf
- https://uploads.strikinglycdn.com/files/fa76199f-0022-493d-9399-2132ad6f0edd/newufugivami.pdf
- https://uploads.strikinglycdn.com/files/b922deef-f149-4256-a7b2-452083736a85/94618873823.pdf
- https://uploads.strikinglycdn.com/files/3d25fe0b-0307-4b49-a368-b5293c9d2b7a/38558569138.pdf
- https://uploads.strikinglycdn.com/files/e4a8e7f9-804d-46e4-9862-9c7184c6572d/19997977104.pdf
- https://uploads.strikinglycdn.com/files/140f8ff3-acb3-4872-a686-19a94c9eba9f/96000181806.pdf
- https://uploads.strikinglycdn.com/files/a96c7180-7268-45b3-b403-572be0b6989c/80701086935.pdf
- https://site-1037019.mozfiles.com/files/1037019/metefiladekamalinikafis.pdf
- https://site-1036644.mozfiles.com/files/1036644/lupimisisoge.pdf
- https://uploads.strikinglycdn.com/files/3e80a112-2c77-48ee-8c3b-ccaab1c395e6/49830893320.pdf
- https://uploads.strikinglycdn.com/files/a64c5223-fc12-43e3-b6c0-e709a9ed9d56/62006122471.pdf
- https://uploads.strikinglycdn.com/files/6c1342ca-9f6d-4b73-ac4f-8f6dbf9b7ab3/pitizelukokunuvidovede.pdf
- https://uploads.strikinglycdn.com/files/496014ff-bf13-450b-b683-058086cd17b8/68764451130.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1037019.mozfiles.com
- site-1036644.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report