SUSPICIOUS — 99599646723.pdf
SUSPICIOUS — 99599646723.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ac8d712dcdb42a873a07b7b6bcbf1aec9efe54ed797c056192ee444f1d15ed0c - SHA-1:
4d300f3e9001317855ba1fed80e40e463dde940c - MD5:
8d70ced2e6e67df802647a31e5493c0d - ssdeep:
768:agGzpDXvIvTuY51GP5LF2yUVx8WQn8/lCLu5F3lEEzuRZkH:HGFrvQN5185K8h8CLufNuRZkH - TLSH:
T16E33AFF34157DC8CB786AB43A99A204D6546E64C60329BB018E83B3CC57CBBD7F50A60 - Submitted as: 99599646723.pdf
- File type: pdf · Size: 48068 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=the+new+tribe+buchi+emecheta+pdf, https://cdn.shopify.com/s/files/1/0438/7491/0376/files/whirlpool_gas_dryer_thermal_fuse_lowes.pdf, https://cdn.shopify.com/s/files/1/0431/4605/1744/files/54823302998.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=the+new+tribe+buchi+emecheta+pdf
- https://cdn.shopify.com/s/files/1/0438/7491/0376/files/whirlpool_gas_dryer_thermal_fuse_lowes.pdf
- https://cdn.shopify.com/s/files/1/0431/4605/1744/files/54823302998.pdf
- https://cdn.shopify.com/s/files/1/0495/9895/5684/files/31484039109.pdf
- https://cdn.shopify.com/s/files/1/0486/2862/9669/files/47387003259.pdf
- https://uploads.strikinglycdn.com/files/c207f5c6-3800-4659-a26e-d21c8a441d85/54913929335.pdf
- http://selama.touchingchi.com/uploads/1/3/0/7/130739095/7302202.pdf
- http://files.watermelonpatchboutique.com/uploads/1/3/1/6/131606056/04a02493f.pdf
- http://vutedunos.hopehousekanazawa.com/uploads/1/3/2/6/132682694/logajanojegeb_lejuboriwub_pajobugameme.pdf
- https://site-1037022.mozfiles.com/files/1037022/fafalaxivukitevelatob.pdf
- https://site-1037262.mozfiles.com/files/1037262/81027213451.pdf
- https://site-1036799.mozfiles.com/files/1036799/puverasefawomesuxejuzam.pdf
- https://site-1040238.mozfiles.com/files/1040238/nuboperenomoporozasiwe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- selama.touchingchi.com
- files.watermelonpatchboutique.com
- vutedunos.hopehousekanazawa.com
- site-1037022.mozfiles.com
- site-1037262.mozfiles.com
- site-1036799.mozfiles.com
- site-1040238.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report