SUSPICIOUS — 3512900.pdf
SUSPICIOUS — 3512900.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f49730ba0c8211c6071e01dcf26907a612c5eb664728580179e2c1f597103351 - SHA-1:
71d60ac2b66532c72aed40d3165c3de75be5e8c4 - MD5:
ecf64c18ebd03a584c0fc6b6fe2e70d6 - ssdeep:
768:3gGzpDipsH4TBSWh/US33Glfv9lb3C6ALgquzHpjwW6Qzvgbaikq4Bapgf:QGFmpL4CxudcW6QzvaH4Epgf - TLSH:
T108327CF760D3EC8CBA8A9B13AEA705AA548DC7486137DB90418C672CD17C5FE6F11820 - Submitted as: 3512900.pdf
- File type: pdf · Size: 45768 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=the%20spread%20of%20nuclear%20weapons%20an%20end, https://uploads.strikinglycdn.com/files/3fd69f34-5db1-4bc7-8f7e-d51899ae596b/sanipubesekikut.pdf, https://uploads.strikinglycdn.com/files/08895f8a-8026-484a-95bf-c6e50e91721c/sobibererubipokuxuj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=the%20spread%20of%20nuclear%20weapons%20an%20end
- https://uploads.strikinglycdn.com/files/3fd69f34-5db1-4bc7-8f7e-d51899ae596b/sanipubesekikut.pdf
- https://uploads.strikinglycdn.com/files/08895f8a-8026-484a-95bf-c6e50e91721c/sobibererubipokuxuj.pdf
- https://uploads.strikinglycdn.com/files/638655af-8d96-45bf-bb09-89a425aff0eb/vukuwiw.pdf
- https://uploads.strikinglycdn.com/files/7764dfb8-5c5a-4dac-922b-d1d80c9ceddf/balelesosajiwatizokifoten.pdf
- https://uploads.strikinglycdn.com/files/a2bbdf46-f7d4-40f2-bab5-95738a69d097/pakuronapubabivolet.pdf
- https://site-1042013.mozfiles.com/files/1042013/wozuwizewabugegare.pdf
- https://site-1036633.mozfiles.com/files/1036633/91310910461.pdf
- https://site-1036935.mozfiles.com/files/1036935/kazenutaganesafavunupod.pdf
- https://cdn.shopify.com/s/files/1/0268/7156/2434/files/best_weight_loss_apps_for_android.pdf
- https://cdn.shopify.com/s/files/1/0437/1467/4841/files/kagalanisi.pdf
- https://cdn.shopify.com/s/files/1/0480/9877/1097/files/lozexozesigaz.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279037.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/novovuxosijuzuz_wofabunutigepuw_dugulelura.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdf
- https://vefoxetewezelir.weebly.com/uploads/1/3/1/4/131483279/wixidunibi_misexakizinu_madugibofap.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/runemevurexuziwone.pdf
- https://uploads.strikinglycdn.com/files/223528a6-77fa-497c-98d9-95ffad86de3d/96222348083.pdf
- https://uploads.strikinglycdn.com/files/852c7413-78ce-463e-806b-5f6662abd92b/28354054594.pdf
- https://uploads.strikinglycdn.com/files/72e35636-f176-4264-9890-da9dcf246f51/tewilufuvepetadubagivos.pdf
- https://uploads.strikinglycdn.com/files/c7d6cdf2-4c40-40d5-8587-ac42c4a7117e/43795801911.pdf
- https://uploads.strikinglycdn.com/files/36615733-0a86-4359-a67c-e3ee0c56a12a/26557528974.pdf
- https://cdn-cms.f-static.net/uploads/4368238/normal_5f87b68358287.pdf
- https://cdn-cms.f-static.net/uploads/4368238/normal_5f87dd398dce0.pdf
- https://cdn-cms.f-static.net/uploads/4368471/normal_5f882290ad089.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1042013.mozfiles.com
- site-1036633.mozfiles.com
- site-1036935.mozfiles.com
- cdn.shopify.com
- fijojonibiw.weebly.com
- gimejexoxixaza.weebly.com
- keniwuki.weebly.com
- vefoxetewezelir.weebly.com
- genigudepa.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report