SUSPICIOUS — 1a4990.pdf
SUSPICIOUS — 1a4990.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b475fa8fd31ae450c390060a3f0d3aea3d1ecfc4d6a2c30c65d7bcf7acbb1ac6 - SHA-1:
f8d5eb80d1ea100185ff0427a7ef8e8a7d98979f - MD5:
75655cc3f15347b4da128b80d82a5e66 - ssdeep:
768:4gGzpD1pYFgESLSYhH1Cv+1tq5aEDvd7y0Js8KAFklxWOOVcPbpVJ3uo1QUU2pYB:VGFJpYyDLqI67KJAuxWOOinl9+B - TLSH:
T145328CF350B3ED8D7A86EF43ADAE254DA049D6496032D7609588372CC4BC7BD6F00A91 - Submitted as: 1a4990.pdf
- File type: pdf · Size: 44829 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=manually%20install%20addons%20wow, https://uploads.strikinglycdn.com/files/be43d58e-7d5b-46cd-b68a-3b93d99b24dd/49583342681.pdf, https://uploads.strikinglycdn.com/files/95c1292b-0c7f-49a6-863c-024b30f06075/xusuk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=manually%20install%20addons%20wow
- https://uploads.strikinglycdn.com/files/be43d58e-7d5b-46cd-b68a-3b93d99b24dd/49583342681.pdf
- https://uploads.strikinglycdn.com/files/95c1292b-0c7f-49a6-863c-024b30f06075/xusuk.pdf
- https://uploads.strikinglycdn.com/files/6f2475d4-1c03-4633-adac-f16b329bb95e/77778834700.pdf
- https://uploads.strikinglycdn.com/files/0f81ced1-780b-4c51-8e4d-f7a599ed6bae/kesikesubajov.pdf
- https://uploads.strikinglycdn.com/files/0070beaf-ae9e-4a7f-a900-fa76a6c47ec5/lg_gpad_f_7._0_review.pdf
- https://cdn.shopify.com/s/files/1/0477/4694/1084/files/yugioh_tour_guide_link.pdf
- https://cdn.shopify.com/s/files/1/0496/6976/7321/files/denisuligik.pdf
- https://cdn.shopify.com/s/files/1/0499/3335/3118/files/42956694338.pdf
- https://cdn.shopify.com/s/files/1/0486/3757/5326/files/katenaputiromeziwira.pdf
- https://cdn.shopify.com/s/files/1/0500/4876/2016/files/12879539145.pdf
- https://cdn.shopify.com/s/files/1/0501/5873/1429/files/90908089201.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/zanadutut_wexudafenatogun_jetomefoja.pdf
- https://vefozifus.weebly.com/uploads/1/3/4/3/134382693/rilerovubidip_xosivenopu.pdf
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/wewesabaj-vuleledegar-logawuxobe.pdf
- https://pamaridefudeluz.weebly.com/uploads/1/3/0/7/130776324/bofujosipixamepe.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf
- https://luwamagol.weebly.com/uploads/1/3/4/3/134375262/5326292.pdf
- https://wesoxiworikezux.weebly.com/uploads/1/3/1/3/131380467/mosejorun.pdf
- https://denalozi.weebly.com/uploads/1/3/0/7/130776502/5819340.pdf
- https://uploads.strikinglycdn.com/files/80b78177-85fe-44ef-8bfa-6ff05b7e6d4a/88630981176.pdf
- https://uploads.strikinglycdn.com/files/b88f2898-43fb-4b61-a2dd-05e778e669d6/sunawijasadufigez.pdf
- https://uploads.strikinglycdn.com/files/796c389a-42bf-4332-a1ad-15388813474d/zolaziburojokutomipu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- jakedekokobara.weebly.com
- vefozifus.weebly.com
- mojenosude.weebly.com
- pamaridefudeluz.weebly.com
- jatorogerujew.weebly.com
- luwamagol.weebly.com
- wesoxiworikezux.weebly.com
- denalozi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report