SUSPICIOUS — 6714275.pdf
SUSPICIOUS — 6714275.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
dd92231b1495d50fd26c521e5107e792b6e8b9b3680cb2268e946b7bf2012f6f - SHA-1:
27432c04e8b9f6593e1af1764d8368224736ac6d - MD5:
fe6084301fa34ad37e11d1070c40f65f - ssdeep:
768:rgGzpDOePyrE/O+zECr1sauajc7soUUzkYvQvrreZ0FAymAMVie2fRpuZpix5GqU:UGFCePn479TQYvLuOy/qieY8viXfk3 - TLSH:
T197339DF3109BED9D6B8BAB036DEB1198214AC64C6127A65098DC772CD57C1BCBE20960 - Submitted as: 6714275.pdf
- File type: pdf · Size: 48546 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=autocad%20electrical%20drawings%20tutorials%20pdf, https://cdn.shopify.com/s/files/1/0432/1568/3743/files/signal_simulator_wikia.pdf, https://cdn.shopify.com/s/files/1/0482/6988/5601/files/ielts_listening_tips_and_techniques.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=autocad%20electrical%20drawings%20tutorials%20pdf
- https://cdn.shopify.com/s/files/1/0432/1568/3743/files/signal_simulator_wikia.pdf
- https://cdn.shopify.com/s/files/1/0482/6988/5601/files/ielts_listening_tips_and_techniques.pdf
- https://cdn.shopify.com/s/files/1/0429/6038/8252/files/47603673083.pdf
- https://uploads.strikinglycdn.com/files/e87ff3e7-03c9-4370-9964-a85ed0fc7cb8/gevugelifivug.pdf
- https://uploads.strikinglycdn.com/files/7baad151-daa3-49d9-9121-ed5f7c77684a/34511930405.pdf
- https://uploads.strikinglycdn.com/files/53c14d36-898a-437b-9949-8d0f76da5ccb/fonewiwelajejo.pdf
- https://cdn.shopify.com/s/files/1/0437/8332/3806/files/59854771299.pdf
- https://cdn.shopify.com/s/files/1/0495/7437/9676/files/47869478393.pdf
- https://cdn.shopify.com/s/files/1/0433/8935/4142/files/6838538952.pdf
- https://cdn.shopify.com/s/files/1/0498/8796/9438/files/desapelib.pdf
- https://uploads.strikinglycdn.com/files/327a3697-c537-4696-a623-81062b5fc127/96745699923.pdf
- https://uploads.strikinglycdn.com/files/9d03e60f-0e73-43a2-a253-2fad44c72cfb/fijogijiliwerumef.pdf
- https://uploads.strikinglycdn.com/files/6e7c0c1c-54c7-4a62-9d2e-0525d4cdfd0f/86807225417.pdf
- https://uploads.strikinglycdn.com/files/6c5830d1-649e-4bd8-9752-bdc09480d03a/wuzifefixuzezudemodas.pdf
- https://uploads.strikinglycdn.com/files/9c8a663e-672e-4443-ae61-5ef9dc8ddf02/kudozufazuripebe.pdf
- https://cdn.shopify.com/s/files/1/0437/8260/2904/files/42929948522.pdf
- https://cdn.shopify.com/s/files/1/0435/2707/8042/files/dipetasofekerudatakilo.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/tomapetebumobi.pdf
- https://cdn.shopify.com/s/files/1/0437/3449/9493/files/biluxefejibelusowiwitame.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report