SUSPICIOUS — 8801384.pdf
SUSPICIOUS — 8801384.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b24a404635060d60b554a2f4b2a303d65af8872be5fc1ea51d9e0ae66ae3b242 - SHA-1:
3af72e8a8509cc501529c1cdc3c72c587ef9ed65 - MD5:
738d4285a228727e7b2481b2920fe13b - ssdeep:
768:rgGzpD49Mf1S3pXj/pzKg1Jc92QnMNS56ZTqHd/Y7A4ytdoHW2/CMjQk5t5X5I:UGFU9MdSZKdYJywHW8NX5I - TLSH:
T12F316CF35067DD8DB786EB03BDAA105A654AD64CA172D76004CC7B2CC4BC6BE3E11921 - Submitted as: 8801384.pdf
- File type: pdf · Size: 41094 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=structural%20geology%20hatcher%20pdf, https://cdn.shopify.com/s/files/1/0500/2402/2202/files/zarusupaxunej.pdf, https://cdn.shopify.com/s/files/1/0482/4268/8154/files/animal_onesies_for_adults_uk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=structural%20geology%20hatcher%20pdf
- https://cdn.shopify.com/s/files/1/0500/2402/2202/files/zarusupaxunej.pdf
- https://cdn.shopify.com/s/files/1/0482/4268/8154/files/animal_onesies_for_adults_uk.pdf
- https://ziripovopibew.weebly.com/uploads/1/3/0/8/130874468/xapevitonozijopu.pdf
- https://cdn.shopify.com/s/files/1/0440/7322/2294/files/49187612313.pdf
- https://cdn.shopify.com/s/files/1/0497/5978/1023/files/compound_words_worksheet_grade_5.pdf
- https://cdn.shopify.com/s/files/1/0463/1802/6917/files/72090845146.pdf
- https://cdn-cms.f-static.net/uploads/4379733/normal_5f901b0ddc6d0.pdf
- https://cdn.shopify.com/s/files/1/0440/2728/1558/files/capillus_cap_costco_price.pdf
- https://cdn.shopify.com/s/files/1/0496/5593/9236/files/tenozofa.pdf
- https://wivupenoremew.weebly.com/uploads/1/3/0/7/130775018/mumupage.pdf
- https://cdn-cms.f-static.net/uploads/4373301/normal_5f91d6b211a3d.pdf
- https://cdn-cms.f-static.net/uploads/4368467/normal_5f93aa734536c.pdf
- https://cdn.shopify.com/s/files/1/0429/4456/1319/files/spanish_irregular_yo_verbs_worksheet.pdf
- https://cdn-cms.f-static.net/uploads/4377928/normal_5f92c23d7ef19.pdf
- https://cdn.shopify.com/s/files/1/0488/0098/9349/files/43769870140.pdf
- https://cdn-cms.f-static.net/uploads/4390660/normal_5f990744e4e70.pdf
- https://gejatovuri.weebly.com/uploads/1/3/1/4/131406669/wodajomabif.pdf
- https://gumomamomav.weebly.com/uploads/1/3/1/3/131398069/7157948.pdf
- https://cdn.shopify.com/s/files/1/0504/0432/7598/files/gedazigomexu.pdf
- https://cdn-cms.f-static.net/uploads/4368248/normal_5f8ca8011126f.pdf
- https://mipirizu.weebly.com/uploads/1/3/2/6/132682564/8893398.pdf
- https://cdn.shopify.com/s/files/1/0497/5008/1690/files/38158653528.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- ziripovopibew.weebly.com
- cdn-cms.f-static.net
- wivupenoremew.weebly.com
- gejatovuri.weebly.com
- gumomamomav.weebly.com
- mipirizu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report