SUSPICIOUS — 71937465582.pdf
SUSPICIOUS — 71937465582.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a58dd5c0e1a11acd5bada8d52187c90c3b932f1abbc7ecc47f660292138b2843 - SHA-1:
36c19d823bc3e40fd8b8f0793708e444b90aaa72 - MD5:
5adb793811e7d312122744a1cc1d150b - ssdeep:
768:LgGzpDzuXsbNKeXp70fsOE3c2GD9YBT4gt5r/ZCqsl399mkQVIzOfmLuW3B:0GFfuUKeyfsOcc2Gy1jvTXsl39AkM9yJ - TLSH:
T1AA33BFF3806BEC8DB98ABB039EB615546149D6C8712397A450DC373EC47C2BDAE40930 - Submitted as: 71937465582.pdf
- File type: pdf · Size: 48604 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=crack+windows+7+permanent, https://site-1038927.mozfiles.com/files/1038927/zipesatusivezak.pdf, https://site-1037177.mozfiles.com/files/1037177/36416883561.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=crack+windows+7+permanent
- https://site-1038927.mozfiles.com/files/1038927/zipesatusivezak.pdf
- https://site-1037177.mozfiles.com/files/1037177/36416883561.pdf
- https://site-1048453.mozfiles.com/files/1048453/65098889982.pdf
- https://site-1042835.mozfiles.com/files/1042835/lokobenujugoxadodelawi.pdf
- https://uploads.strikinglycdn.com/files/5e79bd69-bcc5-40cf-8396-da773cadfa1b/87875585110.pdf
- https://uploads.strikinglycdn.com/files/4844145d-85fb-4319-9bb0-eac6a96cca5d/86682049391.pdf
- https://uploads.strikinglycdn.com/files/599cfb46-2d50-4d0c-8d85-52f6be600960/kiwaxowabizuxapunelo.pdf
- https://uploads.strikinglycdn.com/files/acc69247-c70e-427f-854c-d09ebcae85f2/91607758402.pdf
- https://uploads.strikinglycdn.com/files/d40af91c-6ded-4269-9048-22713236be8a/55994684069.pdf
- https://site-1044067.mozfiles.com/files/1044067/siniwizakolotezudali.pdf
- https://site-1040888.mozfiles.com/files/1040888/tasiwuteta.pdf
- https://uploads.strikinglycdn.com/files/2e0a1c6f-006c-4e95-b427-074ad86dadb0/todow.pdf
- https://uploads.strikinglycdn.com/files/6c9cb503-247d-4821-9902-0af1e7b024a4/25644184057.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1038927.mozfiles.com
- site-1037177.mozfiles.com
- site-1048453.mozfiles.com
- site-1042835.mozfiles.com
- uploads.strikinglycdn.com
- site-1044067.mozfiles.com
- site-1040888.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report