SUSPICIOUS — 6470882.pdf
SUSPICIOUS — 6470882.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
df57eec8df4da15fe4c94f9dcc0afcb5dca2206849d4f60b07994ec30fa370b5 - SHA-1:
7895435bc0dcbf6e13c6940f7bb797a957688a1e - MD5:
4d3312af517333b09e8c1381b2c4369b - ssdeep:
1536:LGFCpUdDETapZcTySEcpjpwuf9JLB9WltgXvg:qFCpMDEupZceSEGwuf9JLBatd - TLSH:
T12A349EF3109BED0C79CBAF136EAA245D654EE68C6132EB704498676CC47C3AD3E10A51 - Submitted as: 6470882.pdf
- File type: pdf · Size: 52478 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=rolex%20ad%20daytona%201992%20winner%2024%20price%20038, https://site-1038555.mozfiles.com/files/1038555/luwapapokadebijijewutos.pdf, https://site-1038979.mozfiles.com/files/1038979/53700473341.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=rolex%20ad%20daytona%201992%20winner%2024%20price%20038
- https://site-1038555.mozfiles.com/files/1038555/luwapapokadebijijewutos.pdf
- https://site-1038979.mozfiles.com/files/1038979/53700473341.pdf
- https://site-1039529.mozfiles.com/files/1039529/87137629038.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/3990354.pdf
- https://cdn.shopify.com/s/files/1/0477/3937/1676/files/el_amor_debe_ser_firme_james_dobson.pdf
- https://cdn.shopify.com/s/files/1/0432/1945/2072/files/97639300344.pdf
- https://cdn.shopify.com/s/files/1/0481/7125/3911/files/english_root_words_book.pdf
- https://cdn.shopify.com/s/files/1/0433/3889/1419/files/valid_fullz_and_credit_cards.pdf
- https://cdn.shopify.com/s/files/1/0483/3548/7129/files/clear_gel_nail_polish_target.pdf
- https://uploads.strikinglycdn.com/files/aca6172d-632a-4f9c-a434-5e52a0ed1f8b/givipejisikajugi.pdf
- https://uploads.strikinglycdn.com/files/69b92355-36c0-42f4-8b2c-2858518c1ff1/renigutafirevevaw.pdf
- https://uploads.strikinglycdn.com/files/7b7a4e08-0f03-47e0-9ff1-73b56dc9d47d/7657816385.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/3cb113af6.pdf
- https://kidunaxu.weebly.com/uploads/1/3/1/4/131437100/3476921.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf
- https://cdn-cms.f-static.net/uploads/4367617/normal_5f882db16e2d5.pdf
- https://cdn-cms.f-static.net/uploads/4370985/normal_5f8891890e329.pdf
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f8747db9f1d3.pdf
- https://cdn-cms.f-static.net/uploads/4370064/normal_5f87f1f5a9e5d.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f86ffafe31f4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- site-1038555.mozfiles.com
- site-1038979.mozfiles.com
- site-1039529.mozfiles.com
- juragubiv.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- keniwuki.weebly.com
- kidunaxu.weebly.com
- dutitujazekap.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report