SUSPICIOUS — 5996140.pdf
SUSPICIOUS — 5996140.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9765364ab2d6d64f4a57a6d30cbf8c696577e2613f7547e291a0182fe3d6f65f - SHA-1:
d13c38f1b0d3bfd62bdf323441f4879999ddb6f3 - MD5:
895bdd32c77f670eb0c58cabb379af89 - ssdeep:
768:sgGzpDTeSUMsn0RwX0I5ct3ZZ4MYVvDgyrYe+HSzrpzyXlPWYq1Xm:pGFPezOKctJZpYVvbrYxiNzslP3q1Xm - TLSH:
T186328DF3409BED4CBE8BAB435CE70695604A978972279790448C3B2DC4BC6BD7F10920 - Submitted as: 5996140.pdf
- File type: pdf · Size: 44814 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=fundamentos%20de%20economia%20krugman%203%20ed, https://uploads.strikinglycdn.com/files/90e6c8b2-fd43-468d-921a-30811370e157/96031496553.pdf, https://uploads.strikinglycdn.com/files/5039c64d-aa26-4b5c-8ce1-a68d4e0d480f/dolabesujal.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=fundamentos%20de%20economia%20krugman%203%20ed
- https://uploads.strikinglycdn.com/files/90e6c8b2-fd43-468d-921a-30811370e157/96031496553.pdf
- https://uploads.strikinglycdn.com/files/5039c64d-aa26-4b5c-8ce1-a68d4e0d480f/dolabesujal.pdf
- https://uploads.strikinglycdn.com/files/070b309f-1faa-49a4-9f5b-8931d021ea58/72662122773.pdf
- https://uploads.strikinglycdn.com/files/3c2b644c-8a3f-43ec-ac1c-d3a7bd89ac79/96194070144.pdf
- https://cdn-cms.f-static.net/uploads/4369323/normal_5f87c0decb012.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f8714f9d4017.pdf
- https://cdn-cms.f-static.net/uploads/4369166/normal_5f87e62234319.pdf
- https://cdn-cms.f-static.net/uploads/4373522/normal_5f88d313c46c4.pdf
- https://cdn-cms.f-static.net/uploads/4370525/normal_5f88c7c4b967c.pdf
- https://site-1042867.mozfiles.com/files/1042867/45702741478.pdf
- https://site-1038905.mozfiles.com/files/1038905/sajaparipaso.pdf
- https://site-1038303.mozfiles.com/files/1038303/65183966582.pdf
- https://site-1039163.mozfiles.com/files/1039163/nizofebesofutozokawazenuw.pdf
- https://uploads.strikinglycdn.com/files/1673d602-b1b2-4d8e-aad8-44640ce4332a/banuzegige.pdf
- https://uploads.strikinglycdn.com/files/738be59d-24ac-4cd1-9d0f-94b75d218f92/xenaf.pdf
- https://site-1044186.mozfiles.com/files/1044186/animal_crossing_hybrid_flower_guide.pdf
- https://site-1040286.mozfiles.com/files/1040286/zejuzu.pdf
- https://uploads.strikinglycdn.com/files/efd0095c-105e-41bb-8375-cda1d16470a2/18045032829.pdf
- https://uploads.strikinglycdn.com/files/66ee9a09-455e-4bd4-b641-1ea7eec3a2d1/34278075490.pdf
- https://uploads.strikinglycdn.com/files/2c9074dd-2c1d-42e5-9260-b5d0410f1d0e/rixikemenexutexunefi.pdf
- https://uploads.strikinglycdn.com/files/606fa7a5-cfa7-49e3-9a3d-f2187ac414fd/navuwux.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1042867.mozfiles.com
- site-1038905.mozfiles.com
- site-1038303.mozfiles.com
- site-1039163.mozfiles.com
- site-1044186.mozfiles.com
- site-1040286.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report