SUSPICIOUS — 911415.pdf
SUSPICIOUS — 911415.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f436943e2e6a61f17a4fd6f1be8119ca8ce7395b76b3726b42d8583886fe52e2 - SHA-1:
180a2e654af19dbddb9603867f762592719085fe - MD5:
924d36a6f0c998169d60983d1aeb50b8 - ssdeep:
768:BgGzpDhpyV3QejZtVU3V/HLV+xlLbr9+CuT9imKN0kdq39+ec:yGF1pyBdlLgCqimZkC+ec - TLSH:
T1B6308DF300A3DC8DAB87AB03ADE7105A6144C28C6136DB6419DC3B2DD57C6BEBE15921 - Submitted as: 911415.pdf
- File type: pdf · Size: 36733 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=b1%20reading%20comprehension%20exercises%20with%20answers, https://uploads.strikinglycdn.com/files/36fc2d77-f72b-4cbd-8933-bdc2e2ea92ff/cnc_programming_classes.pdf, https://uploads.strikinglycdn.com/files/5eaacefe-cec4-4f4b-95ad-e12eed055d7c/dr_jean_going_on_a_bear_hunt.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=b1%20reading%20comprehension%20exercises%20with%20answers
- https://uploads.strikinglycdn.com/files/36fc2d77-f72b-4cbd-8933-bdc2e2ea92ff/cnc_programming_classes.pdf
- https://uploads.strikinglycdn.com/files/5eaacefe-cec4-4f4b-95ad-e12eed055d7c/dr_jean_going_on_a_bear_hunt.pdf
- https://uploads.strikinglycdn.com/files/60b8b075-69f8-4cd3-bce2-c0afaf6d11e3/potunafapabuwuxanupizi.pdf
- https://uploads.strikinglycdn.com/files/7685d1d0-c70f-4a9f-a905-f2e182e1be18/duwupokuvajeguxezalovu.pdf
- https://cdn.shopify.com/s/files/1/0501/4706/6026/files/variation_worksheet_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0266/8435/8843/files/zevofodipenulolugujo.pdf
- https://cdn.shopify.com/s/files/1/0495/8794/5622/files/1020809683.pdf
- https://cdn.shopify.com/s/files/1/0266/9789/2027/files/waking_up_at_3am.pdf
- https://cdn.shopify.com/s/files/1/0484/6845/9670/files/lurux.pdf
- https://cdn.shopify.com/s/files/1/0499/6120/5924/files/puwogeborabelusukipu.pdf
- https://cdn.shopify.com/s/files/1/0461/8276/0601/files/adjectives_worksheets_for_grade_1.pdf
- https://cdn.shopify.com/s/files/1/0497/6961/1418/files/15164433141.pdf
- https://cdn.shopify.com/s/files/1/0495/6310/7480/files/spikes_tactical_lower_parts_kit_instructions.pdf
- https://cdn.shopify.com/s/files/1/0497/9087/7845/files/bedtime_stories_2008_parents_guide.pdf
- https://uploads.strikinglycdn.com/files/e0a71be7-b253-4b65-b5a5-7ae14fd40983/48376921909.pdf
- https://uploads.strikinglycdn.com/files/89067764-36ef-4f8d-b707-dbe988844f43/kivosunirolanisomebeliki.pdf
- https://cdn.shopify.com/s/files/1/0483/5940/7765/files/programming_collective_intelligence_latest_edition.pdf
- https://cdn.shopify.com/s/files/1/0496/0138/0501/files/nber_patent_data.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report