SUSPICIOUS — 92feee913115.pdf
SUSPICIOUS — 92feee913115.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9b973f9c38e0b6086af33db398f476e5a19a11a0293666098d16c252c2f18935 - SHA-1:
f7885175d29e55b5fe5fab2fcfc2689ccaead88c - MD5:
dbbb15cb13da7c3f4946094d75df0831 - ssdeep:
768:CkgGzpDNe4rGZztEXYsEV3THlkfM4+t/92MiyRHJ/IOjLb823aX+vtywLTNq:WGFBerLHIO3FfvtysTNq - TLSH:
T10D339EF3548BDC4CBA87AB076AF715A96186D74D2132DB6059C8376CC0BC2BDAF10890 - Submitted as: 92feee913115.pdf
- File type: pdf · Size: 48517 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=the%20leadership%20experience%206th%20edition%20pdf, https://uploads.strikinglycdn.com/files/1ddc1f67-71eb-4bb8-8839-0f8d04abb5ec/guzomekiwoxeme.pdf, https://uploads.strikinglycdn.com/files/ffd6b49b-d925-490f-a337-3a8553c0d9e5/9861025849.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=the%20leadership%20experience%206th%20edition%20pdf
- https://uploads.strikinglycdn.com/files/1ddc1f67-71eb-4bb8-8839-0f8d04abb5ec/guzomekiwoxeme.pdf
- https://uploads.strikinglycdn.com/files/ffd6b49b-d925-490f-a337-3a8553c0d9e5/9861025849.pdf
- https://uploads.strikinglycdn.com/files/4d722357-3fcb-464a-a73e-2f05c23fcfc0/6699925308.pdf
- https://cdn-cms.f-static.net/uploads/4366406/normal_5f8728cbeeb3c.pdf
- https://cdn-cms.f-static.net/uploads/4366319/normal_5f879cd7bf04f.pdf
- https://cdn-cms.f-static.net/uploads/4368487/normal_5f87751a49b73.pdf
- https://cdn.shopify.com/s/files/1/0431/0866/3456/files/best_graphics_card_2020_under_500.pdf
- https://cdn.shopify.com/s/files/1/0484/7940/4187/files/43770800675.pdf
- https://cdn.shopify.com/s/files/1/0432/6968/5414/files/suntrust_international_wire_transfer_fee.pdf
- https://cdn.shopify.com/s/files/1/0472/2914/1157/files/bloons_td_4_apk_hacked.pdf
- https://site-1036828.mozfiles.com/files/1036828/vatenejokisopeme.pdf
- https://site-1037261.mozfiles.com/files/1037261/66891877274.pdf
- https://site-1048172.mozfiles.com/files/1048172/3248991218.pdf
- https://site-1043329.mozfiles.com/files/1043329/lawasug.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/6374515.pdf
- https://mokitigek.weebly.com/uploads/1/3/1/6/131606839/011fab.pdf
- https://uploads.strikinglycdn.com/files/bad81b75-ae59-421a-b4dc-27138b7c0354/33293235023.pdf
- https://uploads.strikinglycdn.com/files/c6766a33-0025-4dae-a496-5fd45b5e0c9c/86698119121.pdf
- https://uploads.strikinglycdn.com/files/bb66ee60-2661-462d-bae6-b0ba47791cad/93368902666.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1036828.mozfiles.com
- site-1037261.mozfiles.com
- site-1048172.mozfiles.com
- site-1043329.mozfiles.com
- xojerajap.weebly.com
- mokitigek.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report