SUSPICIOUS — 42398302502.pdf
SUSPICIOUS — 42398302502.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b6ffbb46b1b4b14a9b5d75af785e972a1619b22de6e0929466375a782b6ecbf2 - SHA-1:
fb11455debf642a755f0c9a06e7bdf2ff515adca - MD5:
e1a68411b89218e9b3aca5c1416133ec - ssdeep:
1536:WGFuBLEq2ssEia0ltK7BcOR4TuOyWq2uO9kSzrd:vFu5v2AiQcOR0uOFuO9kS1 - TLSH:
T13433BFF7901BDE8C7B8ABF07EEA91058614AC6C97222976055C87A3CC4BC6FC6D41E50 - Submitted as: 42398302502.pdf
- File type: pdf · Size: 52297 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=vuze+plus+5.+7+activation+code, https://uploads.strikinglycdn.com/files/162db080-3a23-4b83-be9f-a298cfb16f8b/74874055926.pdf, https://uploads.strikinglycdn.com/files/369015e2-b0dd-4f17-a92a-57c43c6f1df3/sasuvibabizusunafudeduwu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=vuze+plus+5.+7+activation+code
- https://uploads.strikinglycdn.com/files/162db080-3a23-4b83-be9f-a298cfb16f8b/74874055926.pdf
- https://uploads.strikinglycdn.com/files/369015e2-b0dd-4f17-a92a-57c43c6f1df3/sasuvibabizusunafudeduwu.pdf
- https://uploads.strikinglycdn.com/files/029bea3c-e2ec-4ca3-a307-48e1b98767a4/95910743353.pdf
- https://uploads.strikinglycdn.com/files/cadd6b5a-67f5-4090-a1c9-a9fcff15b541/gopodukeworo.pdf
- https://uploads.strikinglycdn.com/files/996e390b-51bc-48b8-8cd4-d6f436499af4/47240629442.pdf
- https://site-1036659.mozfiles.com/files/1036659/kagefepafolutirazo.pdf
- https://site-1038919.mozfiles.com/files/1038919/dirozupokomuzosoluwefi.pdf
- https://site-1037121.mozfiles.com/files/1037121/57741054105.pdf
- https://site-1036743.mozfiles.com/files/1036743/45104760844.pdf
- https://site-1038520.mozfiles.com/files/1038520/67692114403.pdf
- https://site-1036944.mozfiles.com/files/1036944/49015189784.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036659.mozfiles.com
- site-1038919.mozfiles.com
- site-1037121.mozfiles.com
- site-1036743.mozfiles.com
- site-1038520.mozfiles.com
- site-1036944.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report