SUSPICIOUS — 95015530042.pdf
SUSPICIOUS — 95015530042.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
ce6abc95d2d08f0d1d1635bb1e00f3b0b675921e21088cfc9a0d4e857014aa5e - SHA-1:
1287351164315a5ecd5c822a7712674e00998fee - MD5:
70fa2f441815585763be7a7cc0c09489 - ssdeep:
1536:/GF9S94AXR1RnC8lvFk3xp5nr9Xh6oRoI:uF9uBVdNAlr9X8ouI - TLSH:
T13D34CFF3406BEE4D7B8AAB03ACFA1454525AD38D6177D6A04598772CD07C2FCAE10861 - Submitted as: 95015530042.pdf
- File type: pdf · Size: 54168 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=benefits+of+budgetary+control+pdf, https://cdn.shopify.com/s/files/1/0483/0494/7362/files/48497487593.pdf, https://cdn.shopify.com/s/files/1/0427/8134/3903/files/79992100053.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=benefits+of+budgetary+control+pdf
- https://cdn.shopify.com/s/files/1/0483/0494/7362/files/48497487593.pdf
- https://cdn.shopify.com/s/files/1/0427/8134/3903/files/79992100053.pdf
- https://cdn.shopify.com/s/files/1/0433/2565/3160/files/bosch_dishwasher_she43_repair_manual.pdf
- https://cdn.shopify.com/s/files/1/0465/2947/8806/files/gap_analysis_template_software.pdf
- https://cdn.shopify.com/s/files/1/0430/6662/2101/files/bayam_oru_payanam_song.pdf
- https://cdn.shopify.com/s/files/1/0428/4012/9692/files/zolabapibew.pdf
- https://cdn.shopify.com/s/files/1/0440/4084/7510/files/master_exploder_chords_sheet.pdf
- https://cdn.shopify.com/s/files/1/0429/9423/7589/files/kixuxomurawiriduvovur.pdf
- https://site-1037152.mozfiles.com/files/1037152/39662798900.pdf
- https://site-1036655.mozfiles.com/files/1036655/surelibiritojimun.pdf
- https://site-1037187.mozfiles.com/files/1037187/lobinavisoluluz.pdf
- https://site-1037241.mozfiles.com/files/1037241/tezelago.pdf
- https://site-1036693.mozfiles.com/files/1036693/zopasip.pdf
- https://site-1037081.mozfiles.com/files/1037081/12686418460.pdf
- https://site-1037081.mozfiles.com/files/1037081/sofotaluzonodinulutoke.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1037152.mozfiles.com
- site-1036655.mozfiles.com
- site-1037187.mozfiles.com
- site-1037241.mozfiles.com
- site-1036693.mozfiles.com
- site-1037081.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report