SUSPICIOUS — 37480573651.pdf
SUSPICIOUS — 37480573651.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
fbdf6bc39585247f32a6971cdbe3e8a15e519c047d344aa6425c8e5479d9d2ab - SHA-1:
2b8cd85c18481f3e953254dd5c1c758d9dd540c1 - MD5:
5b6ea0e0bf8182e14b8926dac0005211 - ssdeep:
768:ngGzpD8aqacow1uwurL6ID7/MxXTU3oXmvCxzuSG45:gGFYStwT/X/zuSG45 - TLSH:
T1892F6BF354E7ED4C7E869B43ADA7119A604AC3895232D7A4448C3B2CD5BC2BE6F01C60 - Submitted as: 37480573651.pdf
- File type: pdf · Size: 34499 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=how+to+watch+football, https://cdn.shopify.com/s/files/1/0485/3301/2635/files/fovofugosanotuji.pdf, https://cdn.shopify.com/s/files/1/0499/9285/9798/files/nature_2_spa_mineral_sanitizer_instructions.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=how+to+watch+football
- https://cdn.shopify.com/s/files/1/0485/3301/2635/files/fovofugosanotuji.pdf
- https://cdn.shopify.com/s/files/1/0499/9285/9798/files/nature_2_spa_mineral_sanitizer_instructions.pdf
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/pequenos_textos_em_ingles_para_iniciantes.pdf
- https://cdn.shopify.com/s/files/1/0481/3881/3589/files/31755225446.pdf
- https://cdn-cms.f-static.net/uploads/4371543/normal_5f8911b0a2a66.pdf
- https://cdn-cms.f-static.net/uploads/4368770/normal_5f91c26058db2.pdf
- https://cdn-cms.f-static.net/uploads/4407070/normal_5f93467ff36b7.pdf
- https://cdn-cms.f-static.net/uploads/4374188/normal_5f8d14e2185c3.pdf
- https://cdn-cms.f-static.net/uploads/4393035/normal_5f934c3518a3c.pdf
- https://folemazilepi.weebly.com/uploads/1/3/1/1/131164248/3470289.pdf
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/bamunekavif-zozisikalafo-lugawo-wurifupit.pdf
- https://gewosawoma.weebly.com/uploads/1/3/0/7/130739201/7410543.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/wotareropajewub.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/kopiwu_gotatumeturi_bovejixegas_vivikow.pdf
- https://uploads.strikinglycdn.com/files/37867643-c3db-4100-8b0c-7f7b69561c67/12360472455.pdf
- https://uploads.strikinglycdn.com/files/478c85a6-b0f5-43f3-a227-97c8b8e11e16/commodore_computer_parts.pdf
- https://uploads.strikinglycdn.com/files/035c3202-d5a0-49e4-afd6-6365dea86d8d/pemalatexosufo.pdf
- https://uploads.strikinglycdn.com/files/fd998e29-2c27-45f6-ad74-bc71bb2623ef/jekufuzatota.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f876249dab88.pdf
- https://cdn-cms.f-static.net/uploads/4380078/normal_5f934510c147d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- folemazilepi.weebly.com
- mojenosude.weebly.com
- gewosawoma.weebly.com
- gimejexoxixaza.weebly.com
- keniwuki.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report