SUSPICIOUS — 1463474.pdf
SUSPICIOUS — 1463474.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
9e3288b6c7f2de2598395be404fbeb142cc3d794636801b8d6a34517e874f0ab - SHA-1:
cdaaca7f7161a96bd980df24c7274a230c9bb7dc - MD5:
72ccbca5d9b8671c21b337b1db227d25 - ssdeep:
768:EgGzpDapQ7iz2PHaHVo8YyRqkn/ekFevZAOJVFm/xf5Yti8yn+52PFy9:xGFGpQ7izteCevOOJVFm/vX8yn+52PFo - TLSH:
T1BF327DF320D7ED8C7A8B5F13AA6712A9648A974C61339390558CB72CC5BC6FD3E00A15 - Submitted as: 1463474.pdf
- File type: pdf · Size: 45006 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=tuff%20stuff%20axt%203%20manual, https://cdn-cms.f-static.net/uploads/4419451/normal_5f979686e3e41.pdf, https://cdn-cms.f-static.net/uploads/4376120/normal_5f8b57bed168b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=tuff%20stuff%20axt%203%20manual
- https://cdn-cms.f-static.net/uploads/4419451/normal_5f979686e3e41.pdf
- https://cdn-cms.f-static.net/uploads/4376120/normal_5f8b57bed168b.pdf
- https://cdn-cms.f-static.net/uploads/4369166/normal_5f87c8e4c30e1.pdf
- https://cdn-cms.f-static.net/uploads/4379359/normal_5f9539c8ad30a.pdf
- https://cdn-cms.f-static.net/uploads/4392210/normal_5f9510eaa91af.pdf
- https://cdn.shopify.com/s/files/1/0496/1114/5365/files/mega_clean_detox_drink_instructions.pdf
- https://uploads.strikinglycdn.com/files/9ac5b52f-cc32-44e7-b3a5-d49d179b1606/lokanidorupetigivaw.pdf
- https://uploads.strikinglycdn.com/files/f1bd139f-3127-4ac8-beb3-ee67fc32c5a3/xasujugokezaw.pdf
- https://zuragani.weebly.com/uploads/1/3/1/4/131438510/dobox-xoxosokin.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/jogowezokuvaxu.pdf
- https://tojaluteder.weebly.com/uploads/1/3/4/3/134384479/wetowile-demapo-folonokevog.pdf
- https://tedinuvade.weebly.com/uploads/1/3/4/3/134348171/fb1e8c82ef1d281.pdf
- https://nopuwilimo.weebly.com/uploads/1/3/4/4/134490360/lumil-tusinenadoto-rugemabi-tapesixowo.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/kopiwu_gotatumeturi_bovejixegas_vivikow.pdf
- https://wojedebaroz.weebly.com/uploads/1/3/1/6/131637691/e29cd1b900a3.pdf
- https://bafovulik.weebly.com/uploads/1/3/1/0/131070506/zofawebilakodogupe.pdf
- https://jorimedazaget.weebly.com/uploads/1/3/0/7/130738946/xozokuzegapalurel.pdf
- https://vakasuvarepem.weebly.com/uploads/1/3/4/3/134328097/zizutejurakun-jowotuxopilexez-vikazogibixarez.pdf
- https://cdn-cms.f-static.net/uploads/4416494/normal_5f97fc1c82ce0.pdf
- https://cdn-cms.f-static.net/uploads/4383460/normal_5f8f931bcbaa7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- zuragani.weebly.com
- zoxuzuxebexot.weebly.com
- tojaluteder.weebly.com
- tedinuvade.weebly.com
- nopuwilimo.weebly.com
- keniwuki.weebly.com
- wojedebaroz.weebly.com
- bafovulik.weebly.com
- jorimedazaget.weebly.com
- vakasuvarepem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report