SUSPICIOUS — 31293399493.pdf
SUSPICIOUS — 31293399493.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c21911cfb73d104a5b5342e17381b71b01dd074a168645d28ac5885c4e8ef208 - SHA-1:
3f0a66c4eb675d0b71341c2b08d77bab24cfad26 - MD5:
4187023ec500a1c24b911ed78868cc78 - ssdeep:
768:sgGzpDuTWnQsseaATZIJ0xcigeNKwQ0cmj9XQA:pGFasaATLgeAwQqj9XQA - TLSH:
T1BC32BEF30497DD8C35C5AB036EAA3569A289D388623797A018DC776CC8BC77DBE50520 - Submitted as: 31293399493.pdf
- File type: pdf · Size: 44663 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=negative+prefixes+adjectives+pdf, https://cdn.shopify.com/s/files/1/0485/9756/5598/files/ridge_rec_center_jobs.pdf, https://cdn.shopify.com/s/files/1/0433/3145/3081/files/67222465445.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=negative+prefixes+adjectives+pdf
- https://cdn.shopify.com/s/files/1/0485/9756/5598/files/ridge_rec_center_jobs.pdf
- https://cdn.shopify.com/s/files/1/0433/3145/3081/files/67222465445.pdf
- https://cdn.shopify.com/s/files/1/0484/2078/2238/files/present_worth_analysis.pdf
- https://cdn.shopify.com/s/files/1/0433/8181/7494/files/a_christmas_carol_act_1_crossword_puzzle_answers.pdf
- https://uploads.strikinglycdn.com/files/e0d25ff1-ac21-48c7-9d4c-c54bbf5cc5ca/gafufafomabalab.pdf
- https://uploads.strikinglycdn.com/files/1953f7c7-c8c9-45f6-8561-c6ea880b4898/dagap.pdf
- https://uploads.strikinglycdn.com/files/98c84127-4ee4-44cb-8ac8-bd56d8a417cb/60517943395.pdf
- https://uploads.strikinglycdn.com/files/16e91ff0-aa0f-46bb-aff7-17f55f3b29f1/juzumejojudemerob.pdf
- https://uploads.strikinglycdn.com/files/de5c72db-4151-4da5-8ec1-5315a2e7e582/xopifulazizetemapit.pdf
- http://files.trinityjamestown.com/uploads/1/3/2/6/132681602/375267.pdf
- http://ladav.alexandrajelleberg.com/uploads/1/3/2/3/132302999/mororib.pdf
- http://zamiwabo.tipsyglasswinery.com/uploads/1/3/2/7/132740829/4b7cb0f7ddc829a.pdf
- http://files.adnpkids.com/uploads/1/3/0/9/130969527/c27efae54d618.pdf
- http://wezabeza.roanyscollectibles.com/uploads/1/3/1/1/131164250/luvazupivu_wotuwenu.pdf
- http://xugutafu.tdsdancespace.com/uploads/1/3/1/3/131398473/vugofu-bodabefokofa.pdf
- http://robone.forhisreign.org/uploads/1/3/1/4/131407089/629bf437.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- files.trinityjamestown.com
- ladav.alexandrajelleberg.com
- zamiwabo.tipsyglasswinery.com
- files.adnpkids.com
- wezabeza.roanyscollectibles.com
- xugutafu.tdsdancespace.com
- robone.forhisreign.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report