SUSPICIOUS — 6716312.pdf
SUSPICIOUS — 6716312.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d4df2f6bb0c504b74ddc82c786691fe54b6229549a174aed46d72c4f8be4e038 - SHA-1:
7a11bee241f59dc0bec31071eec4eb55a5f5f9db - MD5:
78f5a3d3fbea8f4dfd346cf9c9cf663f - ssdeep:
1536:TGFMexXxlOX2LAhH4jUr08D8gO+ZtHSw:iFMexXxlRg4jUrxbtZ - TLSH:
T18C349DF300D7DD4DBB8BDF43ACEB10A5644AD7497137A7A08588266CC0BC6AD7E50A60 - Submitted as: 6716312.pdf
- File type: pdf · Size: 52427 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=john%20bergman%20arthritis%20youtube, https://uploads.strikinglycdn.com/files/64b04196-2a4e-4e29-80c6-6e16b49e283d/99463617452.pdf, https://uploads.strikinglycdn.com/files/972dc0ad-8f34-4bf2-b9e5-d223f9302ca0/medal.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=john%20bergman%20arthritis%20youtube
- https://uploads.strikinglycdn.com/files/64b04196-2a4e-4e29-80c6-6e16b49e283d/99463617452.pdf
- https://uploads.strikinglycdn.com/files/972dc0ad-8f34-4bf2-b9e5-d223f9302ca0/medal.pdf
- https://uploads.strikinglycdn.com/files/36eef294-e33e-4dba-9eae-9255d1288970/64872609567.pdf
- https://uploads.strikinglycdn.com/files/45e0da7b-8a51-4e6e-a15e-7d63d9ea0365/36813247180.pdf
- https://uploads.strikinglycdn.com/files/b37e38e5-d4d0-4c9d-bb03-9d798a25a313/lakewupomutivema.pdf
- https://site-1037897.mozfiles.com/files/1037897/86863110034.pdf
- https://site-1038412.mozfiles.com/files/1038412/57989023608.pdf
- https://site-1043941.mozfiles.com/files/1043941/vidam.pdf
- https://site-1037833.mozfiles.com/files/1037833/sogowizufasepuxim.pdf
- https://site-1039259.mozfiles.com/files/1039259/10524852191.pdf
- https://cdn.shopify.com/s/files/1/0440/5785/4102/files/american_airlines_target_customer.pdf
- https://cdn.shopify.com/s/files/1/0496/1838/7107/files/smoking_london_broil_recipe.pdf
- https://cdn.shopify.com/s/files/1/0480/0505/4623/files/star_trek_fleet_command_all_jellyfish_missions.pdf
- https://cdn.shopify.com/s/files/1/0499/1732/9566/files/venir_future_tense.pdf
- https://cdn.shopify.com/s/files/1/0428/2771/0630/files/raymond_williams_marxism_and_literature.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f8722f5df299.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f87028656adf.pdf
- https://site-1039641.mozfiles.com/files/1039641/fajozoxuxiwo.pdf
- https://site-1039303.mozfiles.com/files/1039303/gupulogenudimubajakut.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f870dca8136f.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f870de46ef56.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f871c378120c.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f8703590d3d4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1037897.mozfiles.com
- site-1038412.mozfiles.com
- site-1043941.mozfiles.com
- site-1037833.mozfiles.com
- site-1039259.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1039641.mozfiles.com
- site-1039303.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report