SUSPICIOUS — 4703048.pdf
SUSPICIOUS — 4703048.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e6a74dae1b44b7c6779c969da185c12467ea1a626e832386670c1ceed7d31e36 - SHA-1:
2bb532cb23d311fa41b40350c6c1fec410825422 - MD5:
fd577054ca966d1d12c197a4c2797bcc - ssdeep:
768:zgGzpDKpjfFHv2aXX//bhg1Swy9jQ+P5Qaav2YeD5sl0wVjea81lB1:MGFupxJQuQaaFeD5sl3dea81lB1 - TLSH:
T16A328DF36097EC4C7D86A713ADBB21595089D34D6232E260459C3B2DD8BC6FDAF10861 - Submitted as: 4703048.pdf
- File type: pdf · Size: 44316 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=lord%20of%20the%20rings:%20conquest, https://uploads.strikinglycdn.com/files/72781947-96cb-469e-ba62-7effe7c63b37/47339825761.pdf, https://uploads.strikinglycdn.com/files/fc9a17a2-6f7f-4fa4-8c46-28fc0a484b94/pusot.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=lord%20of%20the%20rings:%20conquest
- https://uploads.strikinglycdn.com/files/72781947-96cb-469e-ba62-7effe7c63b37/47339825761.pdf
- https://uploads.strikinglycdn.com/files/fc9a17a2-6f7f-4fa4-8c46-28fc0a484b94/pusot.pdf
- https://uploads.strikinglycdn.com/files/560a36ca-e479-4c04-9468-60c32a048d60/pidibu.pdf
- https://uploads.strikinglycdn.com/files/93e05642-4ecd-43de-b55a-4af01c880851/bejifodox.pdf
- https://cdn.shopify.com/s/files/1/0482/7224/4900/files/goropelofixajololot.pdf
- https://cdn.shopify.com/s/files/1/0433/4374/1083/files/sunitebebivejere.pdf
- https://cdn.shopify.com/s/files/1/0499/4138/1274/files/bng_hp_m_guitar_y.pdf
- https://cdn.shopify.com/s/files/1/0480/9329/8851/files/japanese_flower_tattoos.pdf
- https://cdn.shopify.com/s/files/1/0432/8839/5936/files/honda_cbr_600_rr_2008_service_manual.pdf
- https://uploads.strikinglycdn.com/files/b4dc1900-d28e-4bf9-9ce7-29428eb0d636/xokowobifizuxuladuz.pdf
- https://uploads.strikinglycdn.com/files/e231f221-9164-4b48-85c6-29c9c33877f8/58129036456.pdf
- https://uploads.strikinglycdn.com/files/6902df66-6362-411d-94ae-b7eff3bcd687/tewunoj.pdf
- https://uploads.strikinglycdn.com/files/83754dd1-5d0a-4263-9339-b362777b10e1/595619572.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f87b4a88ef5b.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f873a413f4ac.pdf
- https://site-1040215.mozfiles.com/files/1040215/23608468165.pdf
- https://site-1044145.mozfiles.com/files/1044145/lujupozu.pdf
- https://site-1042672.mozfiles.com/files/1042672/64377639361.pdf
- https://site-1043666.mozfiles.com/files/1043666/10249859793.pdf
- https://site-1038303.mozfiles.com/files/1038303/nupoboxubemetepuseketer.pdf
- https://uploads.strikinglycdn.com/files/1afd86d9-7c17-4bc7-b4cc-fd75c925d6a1/gupowodukuwinubigokifom.pdf
- https://uploads.strikinglycdn.com/files/0ad906b6-d429-466a-b727-b5e6757d1de8/70477971490.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1040215.mozfiles.com
- site-1044145.mozfiles.com
- site-1042672.mozfiles.com
- site-1043666.mozfiles.com
- site-1038303.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report