SUSPICIOUS — 5381924.pdf
SUSPICIOUS — 5381924.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e52e3712704428c38d92854e73a69eb07939ac59c759538cbe70a73444c30c5c - SHA-1:
85cd8f54c4d771423470a8c05d2f2166560bc316 - MD5:
18065c6025d912b18771021754b13eb9 - ssdeep:
1536:2GFTzVUQpfY/gkKc1jvTBDCt42z0ghi5kkrLd:PFTzKQpnkK+1DCtBzz8V - TLSH:
T16734AEF350A3ED4C7ACB9F43AEAE2A4A6149D6486132D7705988673DC0BC7BE3D00951 - Submitted as: 5381924.pdf
- File type: pdf · Size: 56471 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=pdf%20editing%20software%20free%20online, https://uploads.strikinglycdn.com/files/8730ef6f-ae7f-450d-b734-bd74c4def9a5/21673770806.pdf, https://uploads.strikinglycdn.com/files/f3270edb-9199-452c-8511-30eaaa5ae2fc/mofotizotuzunaweb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=pdf%20editing%20software%20free%20online
- https://uploads.strikinglycdn.com/files/8730ef6f-ae7f-450d-b734-bd74c4def9a5/21673770806.pdf
- https://uploads.strikinglycdn.com/files/f3270edb-9199-452c-8511-30eaaa5ae2fc/mofotizotuzunaweb.pdf
- https://uploads.strikinglycdn.com/files/821a7971-fe2b-4e1a-ad99-63117469e2dd/sizulimapume.pdf
- https://uploads.strikinglycdn.com/files/5fbd0c36-825f-4987-80a8-91e2d723db53/40269760505.pdf
- https://uploads.strikinglycdn.com/files/96653b2c-959a-4cea-852b-8d90a29b2b64/4849291382.pdf
- https://s3.amazonaws.com/fedufiporara/anlage_v_2017_formular.pdf
- https://s3.amazonaws.com/mafavuzenoliki/64612187506.pdf
- https://uploads.strikinglycdn.com/files/4d01e71b-5cb6-4959-807a-d56c86093aa3/tarifulukizi.pdf
- https://uploads.strikinglycdn.com/files/d073b694-01ab-483f-a05e-b63181ba156c/samantha_wonks_padilla_sucre.pdf
- https://uploads.strikinglycdn.com/files/37402203-96fd-4acd-a150-2267c71df3fd/54996728887.pdf
- https://uploads.strikinglycdn.com/files/3f4119c7-c497-4053-a6e4-242154a98a91/72409968670.pdf
- https://xukaxikerebata.weebly.com/uploads/1/3/4/0/134042698/kufofupow_ruzevemonobo_neniz_dopawi.pdf
- https://dajapofijakaf.weebly.com/uploads/1/3/4/2/134266914/tuvezejam.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/4942765.pdf
- https://uploads.strikinglycdn.com/files/d29a73a8-e32d-460a-8ea3-7270a1b5917e/programme_tv_cin_frisson.pdf
- https://uploads.strikinglycdn.com/files/9d780296-e9bf-4d74-849b-6bfef288d6d5/distributive_adjectives_exercises_wi.pdf
- https://uploads.strikinglycdn.com/files/feca1469-5205-45dd-a6a6-69bc4f7be928/7928666505.pdf
- https://uploads.strikinglycdn.com/files/3430aaf3-f9bc-44f7-91e7-b83d95c2baea/7610122838.pdf
- https://uploads.strikinglycdn.com/files/e9f8fe6f-9bfd-4ade-bffb-457bbc290d61/butugorumamanira.pdf
- https://cdn.shopify.com/s/files/1/0502/7604/0889/files/88046756167.pdf
- https://cdn.shopify.com/s/files/1/0486/1132/8160/files/xokavo.pdf
- https://cdn.shopify.com/s/files/1/0486/2790/8766/files/mosbys_drug_guide_for_nursing_students.pdf
- https://cdn.shopify.com/s/files/1/0500/3103/4539/files/mini_mental_status_exam_in_spanish.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- xukaxikerebata.weebly.com
- dajapofijakaf.weebly.com
- jufaxexave.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report