SUSPICIOUS — 819677391.pdf
SUSPICIOUS — 819677391.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
a905dc370b29474082ecaa847e60467c9692f2f8b9d0c7de062952240c5f86fb - SHA-1:
4acfeb130547eac9eaf0ab462bbecc2e62011169 - MD5:
c65a8a185fff23b50e7317ff29ecf328 - ssdeep:
768:ngGzpDEhYN3LGqywhqCZFsBVnctsijX0cP/ZM:gGFwGbGqvYCZFsnctbP/ZM - TLSH:
T17F319DF794DBED5C7A8A6703ACF310649146D788A132A76054CD7B2DC0BC6BEBE00961 - Submitted as: 819677391.pdf
- File type: pdf · Size: 40626 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=hallelujah+nuty+na+fortepian+pdf, https://uploads.strikinglycdn.com/files/fcd434e9-f8bd-4f53-a0ff-7c4a0a4303c4/12779463753.pdf, https://uploads.strikinglycdn.com/files/c81040f5-92ba-4e8b-82b7-c1d857de255e/xilepafalabuguxon.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=hallelujah+nuty+na+fortepian+pdf
- https://uploads.strikinglycdn.com/files/fcd434e9-f8bd-4f53-a0ff-7c4a0a4303c4/12779463753.pdf
- https://uploads.strikinglycdn.com/files/c81040f5-92ba-4e8b-82b7-c1d857de255e/xilepafalabuguxon.pdf
- https://uploads.strikinglycdn.com/files/c757cf14-4f72-4109-8925-348c9cc6a8a2/91898919401.pdf
- https://uploads.strikinglycdn.com/files/978277c3-a7f7-4293-a4e8-69fffe3017ce/sajosopela.pdf
- https://uploads.strikinglycdn.com/files/eeadef2e-5ac1-4b0f-bb73-57aec97b96dd/13781811938.pdf
- https://uploads.strikinglycdn.com/files/ecfa7a47-8662-4147-bdd9-d93c64fe11b9/xirepuvazitigosime.pdf
- https://uploads.strikinglycdn.com/files/35c5533d-4441-467e-b237-b49c7ce0bcf2/69616766133.pdf
- https://uploads.strikinglycdn.com/files/5a5d6077-993e-459f-ba90-5ec0439037d4/tututepexosezapodiraru.pdf
- https://uploads.strikinglycdn.com/files/d1906980-2b5d-45d2-9fd3-59b4212779ba/xelerob.pdf
- https://uploads.strikinglycdn.com/files/4302833a-f1d5-4896-87f4-ced08a87a7a2/bavanatixusararevokew.pdf
- https://uploads.strikinglycdn.com/files/3181eace-d85b-4e66-aa75-2240a36962ab/68996791253.pdf
- https://uploads.strikinglycdn.com/files/0bba6a4a-378a-4736-bc6b-a68c4a1fd07a/jidenarogotagesisomifan.pdf
- https://site-1036724.mozfiles.com/files/1036724/dusesog.pdf
- https://site-1038455.mozfiles.com/files/1038455/77188618376.pdf
- https://site-1037188.mozfiles.com/files/1037188/mozob.pdf
- https://site-1036873.mozfiles.com/files/1036873/22683665405.pdf
- https://site-1037082.mozfiles.com/files/1037082/27491990597.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036724.mozfiles.com
- site-1038455.mozfiles.com
- site-1037188.mozfiles.com
- site-1036873.mozfiles.com
- site-1037082.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report