SUSPICIOUS — 2479b4095aae4d5.pdf
SUSPICIOUS — 2479b4095aae4d5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c532762fb0bf0735d2bc9ae918d8468991d01a8427b7cbf4496d348d367d6872 - SHA-1:
9a70edb6b73dcc83402ff2fe399e501a20af4242 - MD5:
ac1a8f0c3ecfb8b2e3bf501e3c971ae6 - ssdeep:
1536:PGFgp8EJVTB3oKnHsxNMXxw/yG93XHDlfpFv9rmk1AWvrEA28VDs:+Fgp8+gesxNMXxSyeXpDJZHrETh - TLSH:
T16F338DF75067EC8C7A8A6B03ADFB016EA049D7496122EB900488772DD47C6FDBF20651 - Submitted as: 2479b4095aae4d5.pdf
- File type: pdf · Size: 51115 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=geometry%20worksheet%20congruent%20triangl, https://site-1039576.mozfiles.com/files/1039576/64902123392.pdf, https://site-1039811.mozfiles.com/files/1039811/mazuleg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=geometry%20worksheet%20congruent%20triangl
- https://site-1039576.mozfiles.com/files/1039576/64902123392.pdf
- https://site-1039811.mozfiles.com/files/1039811/mazuleg.pdf
- https://site-1038422.mozfiles.com/files/1038422/97152265473.pdf
- https://site-1045404.mozfiles.com/files/1045404/63394939001.pdf
- https://site-1039642.mozfiles.com/files/1039642/18629469648.pdf
- https://uploads.strikinglycdn.com/files/e28dc4a1-2f31-48a8-a754-14194cccaba3/80072662609.pdf
- https://uploads.strikinglycdn.com/files/efac170e-b6f6-47e0-968d-c530713160e6/93747673870.pdf
- https://uploads.strikinglycdn.com/files/65bfdf9a-3956-4f4a-b79d-f9e5f8b3c590/nafekesofukepifag.pdf
- https://uploads.strikinglycdn.com/files/d6ee6e5f-ee22-4ce9-9271-f627d2a697fb/vefelubebazetugegabu.pdf
- https://uploads.strikinglycdn.com/files/f5409926-e34b-4808-976d-3f50db90429b/26495330501.pdf
- https://site-1040177.mozfiles.com/files/1040177/fofidom.pdf
- https://site-1038338.mozfiles.com/files/1038338/nanuroxajikoruxujixumun.pdf
- https://site-1038694.mozfiles.com/files/1038694/riwusagutoxuxafef.pdf
- https://gozofuma.weebly.com/uploads/1/3/0/8/130874065/worojufifo-duragudinepusi.pdf
- https://kekerisasil.weebly.com/uploads/1/3/0/7/130775365/1219044.pdf
- https://cdn.shopify.com/s/files/1/0481/6610/9335/files/beyond_the_basics_boutique.pdf
- https://cdn.shopify.com/s/files/1/0477/0119/6966/files/duzija.pdf
- https://cdn.shopify.com/s/files/1/0488/0118/5957/files/48925232465.pdf
- https://cdn.shopify.com/s/files/1/0501/6636/6363/files/one_piece_filler_arcs.pdf
- https://uploads.strikinglycdn.com/files/6a4621e5-65fe-43e8-819e-1b2c73edce6b/36486620788.pdf
- https://uploads.strikinglycdn.com/files/02f50b3e-63d7-4ed9-a247-a638f3d22c9e/25039450336.pdf
- https://uploads.strikinglycdn.com/files/f025c112-02ce-4399-a6e1-e51a270f7616/bunuwovowarob.pdf
- https://uploads.strikinglycdn.com/files/9f6de584-2244-49d2-9f8f-f9a1552f96e9/13911709183.pdf
- https://uploads.strikinglycdn.com/files/326974cd-a937-476e-9cb4-cfc4fa45ed21/voxisatomumerawibux.pdf
Embedded domains
- ggtraff.ru
- site-1039576.mozfiles.com
- site-1039811.mozfiles.com
- site-1038422.mozfiles.com
- site-1045404.mozfiles.com
- site-1039642.mozfiles.com
- uploads.strikinglycdn.com
- site-1040177.mozfiles.com
- site-1038338.mozfiles.com
- site-1038694.mozfiles.com
- gozofuma.weebly.com
- kekerisasil.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report