SUSPICIOUS — 2597280.pdf
SUSPICIOUS — 2597280.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ed93a23bc6b77d709c8a3c0ba55e311446d003ddc21dae1621f1031eaba7776a - SHA-1:
608847cb5c52d60695f4ae422fb3a9b5e5c3b19c - MD5:
387eac394233ec39065290f5b9c528f4 - ssdeep:
768:+gGzpDHp7KxWS1J00OxkrPFYPmzUCOz30ziULNkCeZWAeTC0kM5kJ6R7UaW5:7GFzp7Kx5WKJkCesS00J6CaW5 - TLSH:
T140338EF350E3ED4D7A879B136EDA256A918ADB4D603297A0158C372CC4BC6AC7F40921 - Submitted as: 2597280.pdf
- File type: pdf · Size: 48340 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=how%20to%20delete%20zoosk%20on%20i%20phone, https://cdn.shopify.com/s/files/1/0464/1210/3848/files/poisonous_snakes_in_oregon.pdf, https://cdn.shopify.com/s/files/1/0482/3272/6680/files/68052667879.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=how%20to%20delete%20zoosk%20on%20i%20phone
- https://cdn.shopify.com/s/files/1/0464/1210/3848/files/poisonous_snakes_in_oregon.pdf
- https://cdn.shopify.com/s/files/1/0482/3272/6680/files/68052667879.pdf
- https://cdn.shopify.com/s/files/1/0433/2306/4488/files/28047222237.pdf
- https://cdn.shopify.com/s/files/1/0431/8812/5857/files/ischaemic_heart_disease_treatment_guidelines.pdf
- https://cdn-cms.f-static.net/uploads/4365649/normal_5f87535241ce4.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f8725e184009.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f870b862412d.pdf
- https://cdn-cms.f-static.net/uploads/4371265/normal_5f88befc3e1ae.pdf
- https://cdn-cms.f-static.net/uploads/4370288/normal_5f89633633083.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/tudasimudimi.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/xawapebuw.pdf
- https://tunimesepet.weebly.com/uploads/1/3/1/4/131455680/a58016c64.pdf
- https://vabeliguteziji.weebly.com/uploads/1/3/1/3/131379360/rolumesenozovam_jotubon_zojogejinibom_bitigazada.pdf
- https://lotagixowila.weebly.com/uploads/1/3/1/1/131164100/xejuxineredumojozeba.pdf
- https://degujipimisa.weebly.com/uploads/1/3/1/4/131453395/9176008.pdf
- https://towetebofipu.weebly.com/uploads/1/3/1/4/131437669/tumoboga.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/e27909d0be.pdf
- https://cdn-cms.f-static.net/uploads/4372100/normal_5f88a46de8ac3.pdf
- https://cdn-cms.f-static.net/uploads/4369663/normal_5f88c9f334fe3.pdf
- https://cdn-cms.f-static.net/uploads/4368265/normal_5f8a3d323065f.pdf
- https://cdn-cms.f-static.net/uploads/4366961/normal_5f8754b8be686.pdf
- https://cdn-cms.f-static.net/uploads/4366623/normal_5f8747d05b648.pdf
- https://uploads.strikinglycdn.com/files/0813fad7-9e25-4415-8cbb-cb1e7cff17aa/vobogo.pdf
- https://uploads.strikinglycdn.com/files/2e68eae6-bc5e-4529-a8c2-e49a111eba59/mudasif.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- fuparududewon.weebly.com
- tejigenunonim.weebly.com
- tunimesepet.weebly.com
- vabeliguteziji.weebly.com
- lotagixowila.weebly.com
- degujipimisa.weebly.com
- towetebofipu.weebly.com
- gevafitasib.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report