SUSPICIOUS — 421601.pdf
SUSPICIOUS — 421601.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
cce9e2083c915a9e1e8d5d04f1730071ba97ccf420b3d5fbc17ae6276aedce9e - SHA-1:
fa609eaecffb6fceb37db926f45d187c9b1146ff - MD5:
d04ef68a47a5ec5e3eaffed5249ca08f - ssdeep:
768:4gGzpDVeYnwMZuFiHmkfgr+YUruLtl8B1RlQ3kOjWhxmgIFK4q6XqO7qTZIwet:VGFZeLBkl7upUtv6XYNet - TLSH:
T1C1327DF340A7DD4C7A879F1369EA345C9149DB4820729B9109CDBB2CC8BC7BD6E51A10 - Submitted as: 421601.pdf
- File type: pdf · Size: 47464 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=es50r9-55%20100%20manual, https://cdn-cms.f-static.net/uploads/4368492/normal_5f89e7c4c92dd.pdf, https://cdn-cms.f-static.net/uploads/4374519/normal_5f8a5a82885b6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=es50r9-55%20100%20manual
- https://cdn-cms.f-static.net/uploads/4368492/normal_5f89e7c4c92dd.pdf
- https://cdn-cms.f-static.net/uploads/4374519/normal_5f8a5a82885b6.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f875f23c3213.pdf
- https://uploads.strikinglycdn.com/files/574f9963-e9ee-48bf-ade7-148085f17337/seviro.pdf
- https://cdn.shopify.com/s/files/1/0431/8543/8884/files/radezowaw.pdf
- https://cdn.shopify.com/s/files/1/0437/0222/3013/files/christmas_eve_communion_liturgy.pdf
- https://uploads.strikinglycdn.com/files/487ca9e8-0cba-4ddb-9cea-b99fb0201d87/92695500250.pdf
- https://uploads.strikinglycdn.com/files/254804f8-d63b-4da0-9719-591dfae03044/fesajoxete.pdf
- https://uploads.strikinglycdn.com/files/96954a3f-4625-4bfa-a74b-4d2540b77721/vujabi.pdf
- https://uploads.strikinglycdn.com/files/795394be-9429-4731-8575-d02d78b61700/wemulefirisateg.pdf
- https://uploads.strikinglycdn.com/files/5bb6f032-1a32-4ac5-8fbe-f5aa7c4eaaa8/vejigajuwibakeda.pdf
- https://uploads.strikinglycdn.com/files/cce5474e-4dde-4764-9751-df9fb2c5e53c/jbl_charge_4_release_date.pdf
- https://uploads.strikinglycdn.com/files/d71be1d2-9d4e-4c3c-b2ad-7b0b453d4313/keruzubanejuwakuwuxujimod.pdf
- https://cdn.shopify.com/s/files/1/0428/9118/2243/files/luffy_gear_4_wallpaper_android.pdf
- https://cdn.shopify.com/s/files/1/0482/9731/2424/files/kroger_blood_pressure_monitor_wrist.pdf
- https://cdn.shopify.com/s/files/1/0268/8129/4505/files/antigone_dudley_fitts_and_robert_fitzgerald.pdf
- https://cdn.shopify.com/s/files/1/0434/1461/8277/files/pukez.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report