SUSPICIOUS — 1673551.pdf
SUSPICIOUS — 1673551.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a48d8a07efeaa62383382cd4dc4e6859e686ce6ab35e42f2acb1e320a9577457 - SHA-1:
4faff7c77c95fcde001b55f6ec3cde91b280b04a - MD5:
22102e802317fd8e813a788e5929a852 - ssdeep:
768:mgGzpDdpg4ouIIoWL3LQkZGF1Q9R6nBOqDKUAubJQ8aR6se0GAxM0adk6kbMoW:zGFxpKwcIKKUxbilJ/GAxMnddkbMoW - TLSH:
T1AD319CF3508BEC4C7A839B13ADE624295589D38A6226D7A044CC3B2DC4BCBBD7F11950 - Submitted as: 1673551.pdf
- File type: pdf · Size: 41778 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ek%20ladki%20ko%20dekha%20to%20aisa%20laga%20kumar%20sanu%20mp3%20download, https://uploads.strikinglycdn.com/files/88e0817d-774f-4f7c-8667-2e59bc6ebcb7/57827586520.pdf, https://uploads.strikinglycdn.com/files/e4f3767d-322f-4266-a2ce-923e6f6cee05/best_mechromancer_build_solo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ek%20ladki%20ko%20dekha%20to%20aisa%20laga%20kumar%20sanu%20mp3%20download
- https://uploads.strikinglycdn.com/files/88e0817d-774f-4f7c-8667-2e59bc6ebcb7/57827586520.pdf
- https://uploads.strikinglycdn.com/files/e4f3767d-322f-4266-a2ce-923e6f6cee05/best_mechromancer_build_solo.pdf
- https://uploads.strikinglycdn.com/files/cfb0c736-eeca-4540-8fc4-b9dbcae74e36/pupelewawonesokojoj.pdf
- https://uploads.strikinglycdn.com/files/f5bd732b-cf73-4928-bd3c-3fac29d0971a/42261181633.pdf
- https://cdn.shopify.com/s/files/1/0465/9324/5349/files/microsoft_surface_mobile_mouse_instructions.pdf
- https://cdn.shopify.com/s/files/1/0472/3130/3845/files/52485915233.pdf
- https://cdn.shopify.com/s/files/1/0480/7236/0093/files/71781313483.pdf
- https://cdn.shopify.com/s/files/1/0268/8224/4802/files/5e_giant_coral_snake.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/misobefogurivo.pdf
- https://fagisidide.weebly.com/uploads/1/3/2/6/132682833/c756a.pdf
- https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/gexujikotavo-wuzov-kafetaxexid.pdf
- https://uploads.strikinglycdn.com/files/1b8221e4-d3be-41de-85ba-0a35f6ce9dec/55702705445.pdf
- https://uploads.strikinglycdn.com/files/4daf9478-a227-436e-81ed-042fdf92268a/4789173638.pdf
- https://uploads.strikinglycdn.com/files/d3b304e1-a21d-4f4d-a1f4-483b243772e3/13023162014.pdf
- https://uploads.strikinglycdn.com/files/c8b4c0e6-a2fc-46aa-82ca-62f01018df3a/4097120007.pdf
- https://uploads.strikinglycdn.com/files/78962a5a-38da-4e04-b23e-033214b2c8df/zusufuruginakudekonatiti.pdf
- https://cdn-cms.f-static.net/uploads/4366647/normal_5f8a01a1096e1.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f8736aa8ebad.pdf
- https://cdn-cms.f-static.net/uploads/4367667/normal_5f885c93ad326.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f876739da069.pdf
- https://cdn-cms.f-static.net/uploads/4366654/normal_5f8766221a3f7.pdf
- https://cdn-cms.f-static.net/uploads/4366660/normal_5f87543e79c4e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- boguvetasitob.weebly.com
- fagisidide.weebly.com
- naxesitigas.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report