SUSPICIOUS — 85203083198.pdf
SUSPICIOUS — 85203083198.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
9514fd664216a0f8a73dfe161d47a0ba2498dac42501e925aa0e2f3843297be8 - SHA-1:
3b29e6f7f8ca8df6cc3f20c108d0547fb9c72f30 - MD5:
d29f3c836315525839f5edb051360ef4 - ssdeep:
1536:TGF0/T4phD13ZY0hkbDav/Btv/CqtJSec0V:iF0/mxhZY0GbAt3NqeZ - TLSH:
T15936CFF3106BDD4CBAC79F935DB2105D614987887133A66888C9736CC0BC6BCAF25862 - Submitted as: 85203083198.pdf
- File type: pdf · Size: 65492 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=el+federalismo+en+mexico+pdf, http://rimidax.carolynbeachinn.com/uploads/1/3/2/6/132695832/vawekegiso_wukawof.pdf, http://files.strayashop.com/uploads/1/3/1/8/131871537/befoxida.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=el+federalismo+en+mexico+pdf
- http://rimidax.carolynbeachinn.com/uploads/1/3/2/6/132695832/vawekegiso_wukawof.pdf
- http://files.strayashop.com/uploads/1/3/1/8/131871537/befoxida.pdf
- http://files.bsbdemocrats.org/uploads/1/3/1/3/131378816/puduwimal.pdf
- https://uploads.strikinglycdn.com/files/d2b524c1-3d48-489f-9136-6978e9f36d55/navenezidovekiwo.pdf
- https://uploads.strikinglycdn.com/files/4e6d39cd-27e3-4d52-adf5-4b76cb50bd0a/67630601446.pdf
- https://uploads.strikinglycdn.com/files/a1525f6c-9682-4697-b3ce-0879ade3a7ab/52060015044.pdf
- https://uploads.strikinglycdn.com/files/5ec9d2a6-5e3f-4612-8087-9d3c38841aee/pabilofemipudanoduzetu.pdf
- https://uploads.strikinglycdn.com/files/01efe4f2-2d71-465a-8ce4-cea8a01fd6ed/23306871016.pdf
- https://site-1037246.mozfiles.com/files/1037246/70978534468.pdf
- https://site-1037842.mozfiles.com/files/1037842/70073906519.pdf
- https://site-1036665.mozfiles.com/files/1036665/vomisolomamegi.pdf
- https://site-1037184.mozfiles.com/files/1037184/lavisaxexuzexagatufupop.pdf
- https://site-1036722.mozfiles.com/files/1036722/kotolinufilemunapoz.pdf
- https://site-1037865.mozfiles.com/files/1037865/rigagerisunupovibefe.pdf
- https://site-1036830.mozfiles.com/files/1036830/74782527152.pdf
- https://site-1036635.mozfiles.com/files/1036635/38374856024.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- rimidax.carolynbeachinn.com
- files.strayashop.com
- files.bsbdemocrats.org
- uploads.strikinglycdn.com
- site-1037246.mozfiles.com
- site-1037842.mozfiles.com
- site-1036665.mozfiles.com
- site-1037184.mozfiles.com
- site-1036722.mozfiles.com
- site-1037865.mozfiles.com
- site-1036830.mozfiles.com
- site-1036635.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report