SUSPICIOUS — 94098544725.pdf
SUSPICIOUS — 94098544725.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e053d19aa0b149afc735ff9958bd8f9c1bae4cf0d4888eaa1f49291ce778fa21 - SHA-1:
1a20f340991c8fb20c48da1210a83e4b45adf7db - MD5:
69d90aa1d5671ab9cc39713cc5a856b2 - ssdeep:
768:CCgGzpDavNLqH0L+VDGyQi4+IM5P/rkD433Y:kGFmX+mi4+/P/rD33Y - TLSH:
T1DF2F8EF3009BED8C7A876B03AEA61459654AC34C6227EB6414DC7BBDC5BC1AC7E00D61 - Submitted as: 94098544725.pdf
- File type: pdf · Size: 35435 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=the+dynamics+of+persuasion+5th+edition+pdf, https://uploads.strikinglycdn.com/files/8c621e7a-8c61-4b11-b283-3854598e6283/68323004930.pdf, https://uploads.strikinglycdn.com/files/a7bbccf3-768b-4925-b560-88f65fb9be62/66388448418.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=the+dynamics+of+persuasion+5th+edition+pdf
- https://uploads.strikinglycdn.com/files/8c621e7a-8c61-4b11-b283-3854598e6283/68323004930.pdf
- https://uploads.strikinglycdn.com/files/a7bbccf3-768b-4925-b560-88f65fb9be62/66388448418.pdf
- https://uploads.strikinglycdn.com/files/5b763804-4e7b-4bea-87d5-2249291f8c09/28093380083.pdf
- https://uploads.strikinglycdn.com/files/f1aa22ae-0200-4d9e-9ca8-7ad6290f3df3/firur.pdf
- https://uploads.strikinglycdn.com/files/df65b81c-c0be-415a-8bd2-f96d3d5672ff/74786759570.pdf
- https://uploads.strikinglycdn.com/files/91a99273-3834-492c-8138-4efdce27f880/xudavude.pdf
- https://uploads.strikinglycdn.com/files/44dd72de-5a2b-431a-8835-3f5a5fbf1cd7/25629511968.pdf
- https://uploads.strikinglycdn.com/files/3ef8eda1-fc91-439f-88b1-26ec61ab1bae/sulopexizalutugazafa.pdf
- https://uploads.strikinglycdn.com/files/ac67f439-bc40-48af-a296-a0b9fb6b0017/42373887991.pdf
- https://uploads.strikinglycdn.com/files/39aa6811-efe3-40d3-a980-36a28f9e26b5/42504510970.pdf
- http://puxamo.icanisciolti.com/uploads/1/3/0/7/130775493/6ffcee5b928a6fa.pdf
- http://migol.lynneawashburn.com/uploads/1/3/0/7/130740571/633c6a7d35.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- puxamo.icanisciolti.com
- migol.lynneawashburn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report