SUSPICIOUS — 67927045438.pdf
SUSPICIOUS — 67927045438.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f12a139cb46ca01065beff74ed202cd4d1f00bbeaf2d4257a4595a7b83b49896 - SHA-1:
5d4b5bf8fc4aec244599eb87d2538821b18111a8 - MD5:
bd500d2578720a978157e5e683ed1a85 - ssdeep:
768:ngGzpDDpfaYb+0gjdxyWzXbY07WyL4x8xvUdu+h+7AM6nDGjjFu2CQ:gGFnpeyWLv4xEYu+PPDcFu2CQ - TLSH:
T115339DF34067EE8C7AC7AB53A8B71194A14AC78C7232A75004D87A6DC9BC5BDBF40810 - Submitted as: 67927045438.pdf
- File type: pdf · Size: 47589 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=motos+de+segunda+m%25C3%25A3o+suzuki+v-strom, https://site-1038963.mozfiles.com/files/1038963/zuvalitaviwibimesisujiwel.pdf, https://site-1040175.mozfiles.com/files/1040175/59941679095.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=motos+de+segunda+m%25C3%25A3o+suzuki+v-strom
- https://site-1038963.mozfiles.com/files/1038963/zuvalitaviwibimesisujiwel.pdf
- https://site-1040175.mozfiles.com/files/1040175/59941679095.pdf
- https://site-1036734.mozfiles.com/files/1036734/92356634826.pdf
- https://site-1038943.mozfiles.com/files/1038943/pasisidakisenakose.pdf
- https://site-1036745.mozfiles.com/files/1036745/66054177974.pdf
- https://cdn.shopify.com/s/files/1/0437/8768/1943/files/mountain_heritage_high_school_athletics.pdf
- https://cdn.shopify.com/s/files/1/0433/6936/5654/files/crochet_slippers_pattern_uk.pdf
- https://cdn.shopify.com/s/files/1/0437/3472/8853/files/11647287624.pdf
- https://uploads.strikinglycdn.com/files/dd89269a-0e9d-4c5b-9320-7e792db557e0/65078671274.pdf
- https://uploads.strikinglycdn.com/files/b7492c6d-b71f-4d2f-a2a9-05907f67d5f2/8904907144.pdf
- https://uploads.strikinglycdn.com/files/9bf14055-741a-434e-b721-9a498a2e5677/80260667183.pdf
- https://uploads.strikinglycdn.com/files/424a7376-f90b-4988-9409-496a65b3b546/veluzomed.pdf
- https://uploads.strikinglycdn.com/files/153eff8f-be91-4289-9eaf-ad91d08572d6/64049309412.pdf
- https://cdn.shopify.com/s/files/1/0434/7625/4873/files/lewirijusopanatovisimaj.pdf
- https://cdn.shopify.com/s/files/1/0485/6863/1456/files/93677426604.pdf
- https://cdn.shopify.com/s/files/1/0484/3379/1144/files/fosetodogakowubal.pdf
- https://cdn.shopify.com/s/files/1/0434/1773/1229/files/dinotopia_books.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1038963.mozfiles.com
- site-1040175.mozfiles.com
- site-1036734.mozfiles.com
- site-1038943.mozfiles.com
- site-1036745.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report