SUSPICIOUS — abdae11e2a33bc.pdf
SUSPICIOUS — abdae11e2a33bc.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
9de36883d1e13bbc747fcbf0d94d958bb6c6941df4db13d007dd3ba2f0c8940a - SHA-1:
e6f67ef58f7e031e554e88627634397abe953e5a - MD5:
f8a038a53417c4341800305f0579d5e5 - ssdeep:
12288:muGYeNR2YkDX3Tr+SNSkW68WrHw7aAShIDo/ZAFdD:mrH2YOX3T6SNTW63Hs9+Yo/CD - TLSH:
T1C14B22F33767ED4C7C43530755A319A8224DE08862278BEA91D8F75CC6F84AE7E06681 - Submitted as: abdae11e2a33bc.pdf
- File type: pdf · Size: 506520 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=the%20roman%20ritual%20of%20exorcism%20pdf, https://uploads.strikinglycdn.com/files/ad59e8a3-6b94-42bb-93e3-3c0537be71e0/88434990143.pdf, https://uploads.strikinglycdn.com/files/fe133acf-5aad-4bb5-a710-6bd0a1f25ec9/dnd_side_quest_generator.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=the%20roman%20ritual%20of%20exorcism%20pdf
- https://uploads.strikinglycdn.com/files/ad59e8a3-6b94-42bb-93e3-3c0537be71e0/88434990143.pdf
- https://uploads.strikinglycdn.com/files/fe133acf-5aad-4bb5-a710-6bd0a1f25ec9/dnd_side_quest_generator.pdf
- https://uploads.strikinglycdn.com/files/e9a78802-0048-442f-8dba-4fd3223e6e4c/90040291562.pdf
- https://uploads.strikinglycdn.com/files/50f41b5c-1151-4eac-9955-9f2dd841bb94/dokipo.pdf
- https://uploads.strikinglycdn.com/files/1e66fc88-82d5-4ce8-afaf-d713eeae046a/safari_esta_conexo_no__privada_ma.pdf
- https://cdn-cms.f-static.net/uploads/4391008/normal_5f97265a80f77.pdf
- https://cdn-cms.f-static.net/uploads/4374362/normal_5f8e92c94b2d4.pdf
- https://cdn-cms.f-static.net/uploads/4369179/normal_5f9174b1336bf.pdf
- https://cdn-cms.f-static.net/uploads/4367927/normal_5f87d394299ee.pdf
- https://cdn-cms.f-static.net/uploads/4374715/normal_5f90e8e3a48b5.pdf
- https://cdn.shopify.com/s/files/1/0437/0530/3190/files/whatsapp_android_2.3.5_apk_mirror.pdf
- https://cdn.shopify.com/s/files/1/0437/3318/8762/files/roka_charlotte_street_menu.pdf
- https://cdn.shopify.com/s/files/1/0433/5537/3720/files/ballpoint_pen_art.pdf
- https://uploads.strikinglycdn.com/files/61899e26-1eb2-43b4-aeaa-60b55789224f/16474521406.pdf
- https://uploads.strikinglycdn.com/files/5d866c8d-792b-4f2f-a7c3-ba4805a0e3ed/31931100339.pdf
- https://uploads.strikinglycdn.com/files/f1c1bef5-00b0-42fe-9d35-bf952a159ccc/90241475085.pdf
- https://uploads.strikinglycdn.com/files/d57cc1c2-f4bc-4cff-ba22-7f384c3ea357/18417338039.pdf
- https://cdn.shopify.com/s/files/1/0484/7160/5410/files/tirafimil.pdf
- https://cdn.shopify.com/s/files/1/0503/1028/3437/files/chicken_invaders_1_free_download_for_android.pdf
- https://cdn.shopify.com/s/files/1/0482/0890/4346/files/bostitch_6_gallon_air_compressor_user_manual.pdf
- https://cdn.shopify.com/s/files/1/0438/5538/0630/files/access_bars_kitap.pdf
- https://cdn.shopify.com/s/files/1/0431/7626/3841/files/93882227781.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report