SUSPICIOUS — 31441119261.pdf
SUSPICIOUS — 31441119261.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e1cbaa85063730de13599ef3beb3dd602a920dadaaf22f96d245f127a13933c9 - SHA-1:
83185cdd1952d83e7008822c50031a455920406b - MD5:
568aaad89c2db27ae051a01cb51ca4cb - ssdeep:
768:ugGzpD8pHofRJmoGBldp2VcCDtiIdmTVlefRWmUFfRUaJTXDs2:LGFgpIfhtiOmbSWHFfRUiTXDs2 - TLSH:
T1CB329EF35067ED9CBA8AAB03ADFA05591289D38D61329720044C271DE57C7BDAF40961 - Submitted as: 31441119261.pdf
- File type: pdf · Size: 43770 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=simplex+method+theory+pdf, https://uploads.strikinglycdn.com/files/da9cc79a-8725-4d8c-80b2-3eebdd190ccb/41513918314.pdf, https://uploads.strikinglycdn.com/files/bc677045-0dfe-40ab-8a34-ad75541cbc83/goloxo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=simplex+method+theory+pdf
- https://uploads.strikinglycdn.com/files/da9cc79a-8725-4d8c-80b2-3eebdd190ccb/41513918314.pdf
- https://uploads.strikinglycdn.com/files/bc677045-0dfe-40ab-8a34-ad75541cbc83/goloxo.pdf
- https://uploads.strikinglycdn.com/files/b19dc600-6bd1-4b1c-babd-eeeeb8689c19/30199868800.pdf
- https://uploads.strikinglycdn.com/files/359329a9-dfe4-4095-98ce-f14fd5330d43/jafux.pdf
- https://cdn.shopify.com/s/files/1/0477/1525/4428/files/wazudes.pdf
- https://cdn.shopify.com/s/files/1/0496/2287/6324/files/the_black_eyed_peas_imma_be_live.pdf
- https://cdn.shopify.com/s/files/1/0439/7809/6798/files/29218994003.pdf
- https://cdn.shopify.com/s/files/1/0432/2410/5115/files/anti_bullying_quotes_for_adults.pdf
- https://uploads.strikinglycdn.com/files/b58e2e99-acd9-40db-81d1-dc6bbc2d3026/4227210790.pdf
- https://uploads.strikinglycdn.com/files/78eb395b-f9e8-4b54-aea2-6ab67c4bdb4a/jisuvizeni.pdf
- https://site-1036724.mozfiles.com/files/1036724/68384487381.pdf
- https://site-1042940.mozfiles.com/files/1042940/grammar_worksheets_for_high_school_students.pdf
- https://site-1043487.mozfiles.com/files/1043487/dijokefepinadabawafaju.pdf
- https://site-1039900.mozfiles.com/files/1039900/22751681328.pdf
- https://cdn-cms.f-static.net/uploads/4368958/normal_5f87b1021266c.pdf
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f872b29e5270.pdf
- https://cdn.shopify.com/s/files/1/0268/9279/6073/files/far_cry_android_game_download.pdf
- https://cdn.shopify.com/s/files/1/0483/1372/9179/files/81370810828.pdf
- https://cdn.shopify.com/s/files/1/0484/2153/5896/files/menominee_tribal_per_capita_2019.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1036724.mozfiles.com
- site-1042940.mozfiles.com
- site-1043487.mozfiles.com
- site-1039900.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report