SUSPICIOUS — 2987289.pdf
SUSPICIOUS — 2987289.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b5c7dc38b57ac730b0d68f0d8bcadf9909cdaf4d123d9de5ea650bd7981501f4 - SHA-1:
6ac090e1a2e05842400fae7bc47d7cfbadf61bab - MD5:
7c1f687b2f1250eca04ae31beb73fa3e - ssdeep:
768:YgGzpDYpazjci9t4c34uOWuKZMKP1jqei+xjX3OjD9KyRmQnGzWHIB:1GFcpaHOWxdhqH+xjX3OVX3nGzWHIB - TLSH:
T1AD339EF350A3DD8C7A8B5F03AEAA281D958DD78C61329664809C763DC4BC3AD7E50D60 - Submitted as: 2987289.pdf
- File type: pdf · Size: 49102 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=rick%20and%20morty%20game%20recipes, https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/3cb113af6.pdf, https://ridolagu.weebly.com/uploads/1/3/0/7/130775195/diren.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=rick%20and%20morty%20game%20recipes
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/3cb113af6.pdf
- https://ridolagu.weebly.com/uploads/1/3/0/7/130775195/diren.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/d8b4f785f.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/ee3d484850ba95e.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/nakugirupexo.pdf
- https://uploads.strikinglycdn.com/files/f9855fcd-9fe4-4fe8-ab08-84fe6f396169/37849222921.pdf
- https://uploads.strikinglycdn.com/files/2670d044-b0a3-448c-b6b3-cf0652671cd3/76053120636.pdf
- https://uploads.strikinglycdn.com/files/68d3b99b-40c2-4287-b5c5-5e6c536b0647/78657187702.pdf
- https://uploads.strikinglycdn.com/files/362b5967-512d-4a7f-a236-4bde9b033d91/sanivavabonojazomej.pdf
- https://uploads.strikinglycdn.com/files/6279862e-0e80-46fa-98b4-0bf8fb0ff5ec/84717651869.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/sijuwoxujupid.pdf
- https://vadutivolojogo.weebly.com/uploads/1/3/0/8/130813650/00c4cc104857.pdf
- https://uploads.strikinglycdn.com/files/ddfde384-1eb4-43e5-96c8-9445322aa267/64075625269.pdf
- https://uploads.strikinglycdn.com/files/98766c7a-8636-4aae-8a47-076cd8313454/getukomalavesusos.pdf
- https://uploads.strikinglycdn.com/files/aae26753-9000-402f-888b-33138bfea546/fawojaro.pdf
- https://uploads.strikinglycdn.com/files/2da7888d-d1a1-4656-b8e3-e23189d1c74f/buwevevukuku.pdf
- https://site-1038611.mozfiles.com/files/1038611/nenumavulexariwusodofoba.pdf
- https://site-1039490.mozfiles.com/files/1039490/30261470470.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f8715cc9f31f.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f8718dbbf538.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- keniwuki.weebly.com
- ridolagu.weebly.com
- besiwalufeg.weebly.com
- babikovinemixe.weebly.com
- vilukenuxe.weebly.com
- uploads.strikinglycdn.com
- jatorogerujew.weebly.com
- vadutivolojogo.weebly.com
- site-1038611.mozfiles.com
- site-1039490.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report