SUSPICIOUS — 6991176.pdf
SUSPICIOUS — 6991176.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d32fb7c0a4c027528926f61309dc8c13a4490858cbb1947359e7d5c1998bc2a0 - SHA-1:
456713e146505601a27595366e3e3e4e2fff22b8 - MD5:
d80283c0bc6c2ec3a474c70972dfdfcb - ssdeep:
768:egGzpDdp+4cFC47hwtx7lcBtLACVdTCA4kg+5WHWmCnNk8zWVTVfYhQGw:bGF5p347Ay8EW2mCnNzzWNVfYhDw - TLSH:
T1FE326DF300A7EE4C7A8B9B03AEEE255D6149DB88507397A0558C662DC4BC77E3F40A11 - Submitted as: 6991176.pdf
- File type: pdf · Size: 44501 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=david%20weber%20uncompromising%20honor%20epub, https://site-1036918.mozfiles.com/files/1036918/votogomazuv.pdf, https://site-1039779.mozfiles.com/files/1039779/convert_to_word_editabile_online_gratis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=david%20weber%20uncompromising%20honor%20epub
- https://site-1036918.mozfiles.com/files/1036918/votogomazuv.pdf
- https://site-1039779.mozfiles.com/files/1039779/convert_to_word_editabile_online_gratis.pdf
- https://site-1043081.mozfiles.com/files/1043081/dafek.pdf
- https://site-1044113.mozfiles.com/files/1044113/defufirojana.pdf
- https://site-1039802.mozfiles.com/files/1039802/piropopasubopezisezuzil.pdf
- https://site-1037214.mozfiles.com/files/1037214/bilewevanuzepevubarivof.pdf
- https://site-1038777.mozfiles.com/files/1038777/jewupenujuzakosed.pdf
- https://site-1043937.mozfiles.com/files/1043937/provises_ativos_e_passivos_contingentes.pdf
- https://site-1045328.mozfiles.com/files/1045328/mexeradurenibejukuwuze.pdf
- https://site-1043291.mozfiles.com/files/1043291/sijolirogijemexubufi.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f86fe7dee259.pdf
- https://cdn-cms.f-static.net/uploads/4367300/normal_5f87597f3dac0.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86f9fd64eee.pdf
- https://cdn-cms.f-static.net/uploads/4369654/normal_5f8815d7a4d76.pdf
- https://cdn.shopify.com/s/files/1/0483/6638/7363/files/msu_ec_201_syllabus.pdf
- https://cdn.shopify.com/s/files/1/0437/6277/8263/files/75259058782.pdf
- https://cdn.shopify.com/s/files/1/0486/4848/7070/files/gosepef.pdf
- https://uploads.strikinglycdn.com/files/09802be8-f70d-457b-b1a6-a6e0dd061115/putawale.pdf
- https://uploads.strikinglycdn.com/files/895967da-b239-4577-8637-b4c84dbc8940/jakezukotu.pdf
- https://uploads.strikinglycdn.com/files/de62f509-29cb-4210-a39c-5c9b3781e644/97646561417.pdf
- https://uploads.strikinglycdn.com/files/8fb1f791-c264-4b48-b36e-3436987c96de/98280332943.pdf
- https://uploads.strikinglycdn.com/files/f09bfc97-ef67-467d-aaca-9a00225bcbcf/dimalujodefekojege.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- site-1036918.mozfiles.com
- site-1039779.mozfiles.com
- site-1043081.mozfiles.com
- site-1044113.mozfiles.com
- site-1039802.mozfiles.com
- site-1037214.mozfiles.com
- site-1038777.mozfiles.com
- site-1043937.mozfiles.com
- site-1045328.mozfiles.com
- site-1043291.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report