SUSPICIOUS — 3358c4ea5b.pdf
SUSPICIOUS — 3358c4ea5b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
db53887e6c822ba40ee50b8272cd0a58696830f54899940d097cc3ad88bc83db - SHA-1:
0c555ea2f8deaed15e872e54beaea3ebf1bf8eb5 - MD5:
8134f16dbe23c95fa4c39da37848f66c - ssdeep:
768:GtgGzpD5pBi8jHHsXEEvTkrYuldhTSulqYJ5tWJqzb4Io:tGF9psehTSb6zWc4Io - TLSH:
T13E305CF340A7DD4CBAC7DB437DEB286D9486C748A0369AA05598276CD47C3BD2E10E60 - Submitted as: 3358c4ea5b.pdf
- File type: pdf · Size: 37980 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=sword%20art%20online%20episode%2015%20english%20sub, https://site-1048482.mozfiles.com/files/1048482/simutabamuzuroxonut.pdf, https://site-1039721.mozfiles.com/files/1039721/gokamemomis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=sword%20art%20online%20episode%2015%20english%20sub
- https://site-1048482.mozfiles.com/files/1048482/simutabamuzuroxonut.pdf
- https://site-1039721.mozfiles.com/files/1039721/gokamemomis.pdf
- https://site-1038974.mozfiles.com/files/1038974/godisug.pdf
- https://site-1043295.mozfiles.com/files/1043295/nifeb.pdf
- https://site-1036750.mozfiles.com/files/1036750/55829861764.pdf
- https://uploads.strikinglycdn.com/files/31c8cce3-91e9-4784-8fe2-66f445c5e7b7/taravawujalijopopukigaw.pdf
- https://uploads.strikinglycdn.com/files/2d97cc03-5a1f-40cd-96ff-116049783843/gasamusuwudijujeti.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f872af2533e1.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f872b9675451.pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f8728f6bcad3.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f86feec824a7.pdf
- https://uploads.strikinglycdn.com/files/c8b000ec-0039-47ac-b4b8-a368f3dc3a91/rigewabutoruwegin.pdf
- https://uploads.strikinglycdn.com/files/237ca0e4-cb50-4b50-a552-a7a68bf956c4/38417933284.pdf
- https://uploads.strikinglycdn.com/files/37624093-efcc-4d69-8231-757c35913325/dozisatojojofavidigawik.pdf
- https://wuvirinofibugiz.weebly.com/uploads/1/3/1/0/131070402/986ca1.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/jixidused.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/da0366c694e301c.pdf
- https://cdn.shopify.com/s/files/1/0486/3728/0414/files/clash_of_clans_free_gems_hack_2020.pdf
- https://cdn.shopify.com/s/files/1/0497/8386/5506/files/61130766195.pdf
- https://cdn.shopify.com/s/files/1/0437/2257/1930/files/nizarivefud.pdf
- https://cdn.shopify.com/s/files/1/0497/3671/2346/files/kyle_guy_fiance_instagram.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- site-1048482.mozfiles.com
- site-1039721.mozfiles.com
- site-1038974.mozfiles.com
- site-1043295.mozfiles.com
- site-1036750.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- wuvirinofibugiz.weebly.com
- jatorogerujew.weebly.com
- sesuwulot.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report