SUSPICIOUS — 1977073.pdf
SUSPICIOUS — 1977073.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
960745d6287eb1df505bfba7e5172519ba7f1c03fb3c341ef03176369678cb92 - SHA-1:
1fff56c9ae9b8b52e08b6189ab55e3cd15fe4fbe - MD5:
41c68b3067b148b4e1e6a62f99d9ae7a - ssdeep:
768:bgGzpDkpEn9jknLH7L34rjySVP9OPJTPh1Z9B888d8ij6M2QaVWi:kGFApM+L3kySLOJl9ByaijeQaVWi - TLSH:
T1C2337EE35093EC4C7A8E6F43AEAB119A614BE78D31379760148C2B2DD07C5ED3E05962 - Submitted as: 1977073.pdf
- File type: pdf · Size: 47593 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=australian%20visitor%20visa%20subclass%20600%20pdf, https://uploads.strikinglycdn.com/files/a9f57269-a127-4e5e-82bb-18ec2272b183/zipibifamopewumogiwi.pdf, https://uploads.strikinglycdn.com/files/70702a8b-d3f5-4932-befc-d4ddfc33d182/43274907768.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=australian%20visitor%20visa%20subclass%20600%20pdf
- https://s3.amazonaws.com/xanebavifamopez/69577487602.pdf
- https://s3.amazonaws.com/dadupawo/17206796247.pdf
- https://s3.amazonaws.com/ribowexulo/nerve_growth_factors.pdf
- https://uploads.strikinglycdn.com/files/a9f57269-a127-4e5e-82bb-18ec2272b183/zipibifamopewumogiwi.pdf
- https://uploads.strikinglycdn.com/files/70702a8b-d3f5-4932-befc-d4ddfc33d182/43274907768.pdf
- https://uploads.strikinglycdn.com/files/5b732a4b-818c-4cc4-b5e6-a4d00217ffc7/gti_clubsport_2016.pdf
- https://uploads.strikinglycdn.com/files/716d53f2-5063-4ab1-8695-2fb311f5ca08/2.pdf
- https://uploads.strikinglycdn.com/files/4a8aa4d2-9074-46c3-8953-e40550a33e37/koteg.pdf
- https://uploads.strikinglycdn.com/files/8f869f12-3084-4cd2-b444-23e5e1582b89/ruwiwogepuvoderuzib.pdf
- https://uploads.strikinglycdn.com/files/99278052-8f6b-47cd-93e4-e80912afb6dc/ashrae_handbook_2017.pdf
- https://uploads.strikinglycdn.com/files/e6279a58-e245-4c1d-824e-ef0b763c5fa1/23647876397.pdf
- https://uploads.strikinglycdn.com/files/680c80b8-0044-4bfa-9ca5-08601e050966/zopofovuduwaliges.pdf
- https://uploads.strikinglycdn.com/files/3e250fd9-01fc-489d-bdc5-8f7277acf158/68965491912.pdf
- https://uploads.strikinglycdn.com/files/288d42fe-c0c9-407f-a372-2434be214a25/vimepojisunemunebejabal.pdf
- https://uploads.strikinglycdn.com/files/7a141686-117a-4490-8507-f4323374fbaf/nofefikabi.pdf
- https://uploads.strikinglycdn.com/files/b16be10d-fc63-4795-882d-e998b8802ac2/41738711384.pdf
- https://uploads.strikinglycdn.com/files/ae8f902f-c5da-4f2e-8b35-62a660c2d398/woluxade.pdf
- https://uploads.strikinglycdn.com/files/ef2183f4-edb0-43ee-a62c-59dfb4713347/19550174216.pdf
- https://uploads.strikinglycdn.com/files/5e9660a6-0f2d-41f5-bd9b-3771adb98041/tavasetaxozalurawuxejujuj.pdf
- https://uploads.strikinglycdn.com/files/d73b8097-1282-43c4-abfd-f6ffe928f9d0/mapa_conceptual_de_etica_y_moral.pdf
- https://cdn.shopify.com/s/files/1/0440/4012/6614/files/xebuturipibebam.pdf
- https://cdn.shopify.com/s/files/1/0503/0389/3686/files/78170025160.pdf
- https://cdn.shopify.com/s/files/1/0463/5639/8246/files/poker_texas_holdem_live_pro_apk.pdf
- https://cdn.shopify.com/s/files/1/0499/3915/3050/files/3924536497.pdf
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report