SUSPICIOUS — 138013.pdf
SUSPICIOUS — 138013.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b52f79047d96b5e7635d74ea2a0d6079faac294429546d8c3e33320fd0571061 - SHA-1:
9bd962808b3f275e1e8a2a4a416bf0eb3e4c216c - MD5:
8754f2788db988890718def1b357edbd - ssdeep:
768:XgGzpDad9E23jKUMlQqVgNR7z6wWzV6eUEukcKP3q3CCGbbTKO0oWkaZRGQaq4xG:wGFuFtMlQqHAjKP3q3Ctb3KRoWPY1P8 - TLSH:
T127349EF310A7EC4D7A8F6B079DE61559618AD28C7022DB9005CC7B2CD5BC9FE2E10A61 - Submitted as: 138013.pdf
- File type: pdf · Size: 56271 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=balinese%20massage%20techniques%20pdf, https://uploads.strikinglycdn.com/files/783e31f3-d1e1-4fcf-8a52-4d3706af5fd8/27193415352.pdf, https://uploads.strikinglycdn.com/files/fc87e4a6-436c-49e8-902a-b6c94fdd6a62/7880586086.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=balinese%20massage%20techniques%20pdf
- https://uploads.strikinglycdn.com/files/783e31f3-d1e1-4fcf-8a52-4d3706af5fd8/27193415352.pdf
- https://uploads.strikinglycdn.com/files/fc87e4a6-436c-49e8-902a-b6c94fdd6a62/7880586086.pdf
- https://uploads.strikinglycdn.com/files/489e98d8-765c-447a-9595-9c99a05fedb3/bekusefowel.pdf
- https://uploads.strikinglycdn.com/files/5436ebf1-5c97-4d0b-aab0-f72fb22782e5/59982594796.pdf
- https://uploads.strikinglycdn.com/files/1291845e-d416-4a31-a5d1-e8a66b10b179/81356810834.pdf
- https://uploads.strikinglycdn.com/files/cde32606-ace5-447f-bc6b-6aaa69b7004f/valekoze.pdf
- https://uploads.strikinglycdn.com/files/eefa0869-0047-4413-932e-2404e452aef1/27238407373.pdf
- https://uploads.strikinglycdn.com/files/ea49eea8-197e-46c0-85da-f30d8d8b762b/75801413150.pdf
- https://uploads.strikinglycdn.com/files/9ca1721a-77d4-4b48-a6e4-53d83eff2865/mewibuxanebiduxedibaw.pdf
- https://cdn-cms.f-static.net/uploads/4367283/normal_5f8fbc0bb6056.pdf
- https://cdn-cms.f-static.net/uploads/4380379/normal_5f920c1439650.pdf
- https://cdn-cms.f-static.net/uploads/4368745/normal_5f8ba141976b0.pdf
- https://cdn-cms.f-static.net/uploads/4392220/normal_5f92720a9e7f9.pdf
- https://cdn-cms.f-static.net/uploads/4378390/normal_5f9395b1d22b2.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/velowo_dakemolaku.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/1000608.pdf
- https://cdn.shopify.com/s/files/1/0500/4810/6649/files/17148918799.pdf
- https://cdn.shopify.com/s/files/1/0431/9651/4461/files/zopifazewosesunaki.pdf
- https://cdn.shopify.com/s/files/1/0501/8304/5293/files/384463400.pdf
- https://cdn.shopify.com/s/files/1/0438/1225/7952/files/ncert_exemplar_maths_class_9.pdf
- https://cdn.shopify.com/s/files/1/0482/0841/2832/files/jackson_stewart_and_john_cena.pdf
- https://mujetuzavos.weebly.com/uploads/1/3/4/2/134266282/6353692321.pdf
- https://xogexemufak.weebly.com/uploads/1/3/1/4/131437987/xusilijidub-nakegadiv-xigiwusijiketow-zedujamo.pdf
- https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/5281532.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- genigudepa.weebly.com
- fodezamu.weebly.com
- cdn.shopify.com
- mujetuzavos.weebly.com
- xogexemufak.weebly.com
- zegojipoxe.weebly.com
- bafovulik.weebly.com
- rimosuvifakub.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report