SUSPICIOUS — 6089483480.pdf
SUSPICIOUS — 6089483480.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
daedc15d573cf7590c8e81b96b5b2a7dc9bb70d25047ec5c3c69c598fbe86976 - SHA-1:
da1765ff2b5d04bd561ae2b2a0a6c39435ed7534 - MD5:
3e16f1571fdefd116a556f25cb6a0a54 - ssdeep:
768:AgGzpDoMwKbowm6m4W/ALdKb23L1Pg8+h+oVATA0pP+due195sRbdRa:NGF8gh+LA00pKue19KR5Ra - TLSH:
T1EF32AFF35067EC4C6A8EAF83A9A7115A3589C38D7172AA7044C87B2CD43C6AD7D40E51 - Submitted as: 6089483480.pdf
- File type: pdf · Size: 46647 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=2007+nissan+maxima+repair+manual+pdf, https://site-1037130.mozfiles.com/files/1037130/90516985525.pdf, https://site-1036798.mozfiles.com/files/1036798/10630242579.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=2007+nissan+maxima+repair+manual+pdf
- https://site-1037130.mozfiles.com/files/1037130/90516985525.pdf
- https://site-1036798.mozfiles.com/files/1036798/10630242579.pdf
- https://site-1043699.mozfiles.com/files/1043699/pedupavix.pdf
- https://site-1043489.mozfiles.com/files/1043489/63777860363.pdf
- https://cdn.shopify.com/s/files/1/0432/3088/8103/files/nouns_that_start_with_f.pdf
- https://cdn.shopify.com/s/files/1/0437/1768/9512/files/oppositional_gaze_bell_hooks.pdf
- https://cdn.shopify.com/s/files/1/0500/9122/9349/files/62382709599.pdf
- https://cdn.shopify.com/s/files/1/0482/9239/7217/files/algebra_punchline_book_a_answers.pdf
- https://cdn.shopify.com/s/files/1/0482/2908/9434/files/romuwewamesivevebal.pdf
- https://cdn.shopify.com/s/files/1/0430/5590/6967/files/pidikapadam.pdf
- https://cdn.shopify.com/s/files/1/0500/9250/7301/files/john_moore_ac_jobs.pdf
- https://cdn.shopify.com/s/files/1/0496/5990/4163/files/88371029378.pdf
- https://cdn.shopify.com/s/files/1/0433/1061/2635/files/lavivosirune.pdf
- https://cdn.shopify.com/s/files/1/0430/8706/9348/files/94603102091.pdf
- https://cdn.shopify.com/s/files/1/0486/1771/7918/files/pirilamigixomizem.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1037130.mozfiles.com
- site-1036798.mozfiles.com
- site-1043699.mozfiles.com
- site-1043489.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report