SUSPICIOUS — 2062615.pdf
SUSPICIOUS — 2062615.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a54c2c96148c0e49d2eea5c99896bfd3bc7d8d37a8a46b699d896e88a702cd53 - SHA-1:
f47f96b729b8124007b8e1b1429a05ed501f9059 - MD5:
967648abe2c3e64603225980dc93a0f2 - ssdeep:
768:vgGzpDLpqvVfjdak0osQBsp+/6X4wFNMVg1LYhzTa6kwGBc6HuLB4WytAa8El:YGF/pqu4wFKgKhzzkjcfLB4W3a8El - TLSH:
T1E9339DF3609BDD8C7E86EB03BAAA1459658ED74C2033DB5041D8332CC57C2BD6E61960 - Submitted as: 2062615.pdf
- File type: pdf · Size: 51902 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ppt%20to%20pdf%20mac, https://uploads.strikinglycdn.com/files/5c0541fe-9b9b-4cbe-933a-c089f3792d54/worovukunigasetoki.pdf, https://uploads.strikinglycdn.com/files/6086dbf2-18ad-4802-8a22-771a71347958/27766976344.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ppt%20to%20pdf%20mac
- https://uploads.strikinglycdn.com/files/5c0541fe-9b9b-4cbe-933a-c089f3792d54/worovukunigasetoki.pdf
- https://uploads.strikinglycdn.com/files/6086dbf2-18ad-4802-8a22-771a71347958/27766976344.pdf
- https://uploads.strikinglycdn.com/files/db9b794d-570c-4fee-b611-05ea8ea23290/mawabawovujugav.pdf
- https://cdn.shopify.com/s/files/1/0497/2940/5079/files/planta_de_la_vida.pdf
- https://cdn.shopify.com/s/files/1/0438/4784/4000/files/nespresso_manual_citiz.pdf
- https://cdn.shopify.com/s/files/1/0431/3723/7146/files/47090168397.pdf
- https://cdn-cms.f-static.net/uploads/4381748/normal_5f8c46f08c8e7.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f8fcfc035ee2.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f9241563b10a.pdf
- https://cdn.shopify.com/s/files/1/0481/5015/1329/files/passive_esl_exercises.pdf
- https://cdn.shopify.com/s/files/1/0431/5670/1346/files/hyrule_warriors_adventure_mode_search_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/8385/2695/files/ssi-4_reading_passages.pdf
- https://cdn.shopify.com/s/files/1/0484/2717/1997/files/roger_zelaznys_visual_guide_to_castle_amber.pdf
- https://cdn-cms.f-static.net/uploads/4366364/normal_5f877cbf83506.pdf
- https://cdn-cms.f-static.net/uploads/4372358/normal_5f89a6831b859.pdf
- https://cdn-cms.f-static.net/uploads/4371799/normal_5f8917b7d54a6.pdf
- https://uploads.strikinglycdn.com/files/9e213fac-dba0-457b-a567-e103e1ffd233/gemilepibiwix.pdf
- https://uploads.strikinglycdn.com/files/a494442a-83af-474c-97c3-b0cccffedb4a/dobifidapanukereganusejug.pdf
- https://uploads.strikinglycdn.com/files/62af4664-c11f-466d-8469-b416b3e00c78/41828975913.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report