SUSPICIOUS — 62654604788.pdf
SUSPICIOUS — 62654604788.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e509886eb193badc35f62c265f47cc9b0550e760b25c6e9db50d07a8b8d0ce58 - SHA-1:
5a615409a018e7c4f903f9804a6215997314005d - MD5:
2ef820e4118c5378a31800441cb8ae73 - ssdeep:
768:5gGzpDpJDtf3/SmdnfVy/+Ws5gIoYVVA8niWV8YT7xP7AhGywoDb:6GFtTfamdfVuo533LLV8YTl7AhyoDb - TLSH:
T1F833AFF710A7DC8C7B8BBB079AEA5098255696897133A77014887B7CC8BC2BC7D50D41 - Submitted as: 62654604788.pdf
- File type: pdf · Size: 51286 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=independencia+de+america+latina, https://site-1039188.mozfiles.com/files/1039188/zijazuwuj.pdf, https://site-1036783.mozfiles.com/files/1036783/79559458513.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=independencia+de+america+latina
- https://site-1039188.mozfiles.com/files/1039188/zijazuwuj.pdf
- https://site-1036783.mozfiles.com/files/1036783/79559458513.pdf
- https://site-1039270.mozfiles.com/files/1039270/68474236706.pdf
- https://site-1036678.mozfiles.com/files/1036678/xewuxugalekorigipebor.pdf
- https://uploads.strikinglycdn.com/files/d48e9357-ca3b-4eb7-80b6-23581d32757b/ragumovabikebonuf.pdf
- https://uploads.strikinglycdn.com/files/650ea734-d0db-4090-90e8-2d378bb2cd99/41523031270.pdf
- https://uploads.strikinglycdn.com/files/d8ee1ea2-c29d-4b4d-997f-1ba1ebc3dd2e/xuberixewebov.pdf
- https://uploads.strikinglycdn.com/files/bf75d5b9-ec0b-4580-9587-6000a8c5defd/8684489168.pdf
- https://uploads.strikinglycdn.com/files/d3f0929c-c10f-45ee-a73a-3cd980075722/75486141506.pdf
- https://uploads.strikinglycdn.com/files/b4b5d033-f9c8-4fdb-b684-4d29b51da196/zojeno.pdf
- https://uploads.strikinglycdn.com/files/01352c4b-04fa-4cc4-b495-0d15f5ce948c/mokup.pdf
- https://cdn.shopify.com/s/files/1/0437/6975/7850/files/aaa_mid_atlantic_colonial_heights_va.pdf
- https://cdn.shopify.com/s/files/1/0436/3275/4841/files/xunuximapazedixevigoku.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1039188.mozfiles.com
- site-1036783.mozfiles.com
- site-1039270.mozfiles.com
- site-1036678.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report