SUSPICIOUS — 93642214373.pdf
SUSPICIOUS — 93642214373.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ff2499426b8d735f26b322ac2322958c909d06454ad4c772d6c71888453e2c69 - SHA-1:
7b275d4cfd0ac894dd4f233e27ef733607590dcc - MD5:
cdef6b0a72581065d3853bde151b28bd - ssdeep:
768:NgGzpDHDNwcWVro1xu7G/abMIqH+9VYXJE/9a/5Q5jkCChrp0xbwMNZ+xaN+K4Vs:uGFzbuuabb/VQCa25IC8MnOxaN+K4VBm - TLSH:
T1DD328DF3115BEC8C7ACB6F47AEAB0059A086CB8DA132A7514988773CD07C7ED6D10961 - Submitted as: 93642214373.pdf
- File type: pdf · Size: 44242 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=breaking+bad+all+seasons+full+hd+download+1080p+mega, https://site-1036667.mozfiles.com/files/1036667/55310919963.pdf, https://site-1039911.mozfiles.com/files/1039911/6433601566.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=breaking+bad+all+seasons+full+hd+download+1080p+mega
- https://site-1036667.mozfiles.com/files/1036667/55310919963.pdf
- https://site-1039911.mozfiles.com/files/1039911/6433601566.pdf
- https://site-1043337.mozfiles.com/files/1043337/76945525800.pdf
- https://site-1037282.mozfiles.com/files/1037282/76264688963.pdf
- https://site-1036873.mozfiles.com/files/1036873/duwufefukudiwodisorodavu.pdf
- https://cdn.shopify.com/s/files/1/0486/0257/9102/files/photosynthesis_quiz_7th_grade.pdf
- https://cdn.shopify.com/s/files/1/0483/1697/3219/files/candy_crush_hack_android_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0481/8341/0837/files/93152426501.pdf
- https://cdn.shopify.com/s/files/1/0495/9204/1624/files/texujinetedez.pdf
- http://files.eimearmcnally.com/uploads/1/3/1/4/131453723/01bd5.pdf
- http://files.louannbauer.com/uploads/1/3/0/7/130739918/xugubanoginonaxud.pdf
- http://vezeb.moservp.com/uploads/1/3/1/4/131437299/gilisorow-jaxim-pobir.pdf
- http://files.turpinorchestra.org/uploads/1/3/1/4/131483372/a84b4.pdf
- http://xuled.comprehensivewellnesssolutions.com/uploads/1/3/1/4/131413418/rovivatipazi-botugisuda-pijuput-lipajojudowu.pdf
- https://cdn.shopify.com/s/files/1/0435/2573/4552/files/28279696943.pdf
- https://cdn.shopify.com/s/files/1/0483/5436/1493/files/dazey_short_order_chef_manual.pdf
- https://cdn.shopify.com/s/files/1/0484/9339/6130/files/an_unlikely_story_bookstore_plainville_ma.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1036667.mozfiles.com
- site-1039911.mozfiles.com
- site-1043337.mozfiles.com
- site-1037282.mozfiles.com
- site-1036873.mozfiles.com
- cdn.shopify.com
- files.eimearmcnally.com
- files.louannbauer.com
- vezeb.moservp.com
- files.turpinorchestra.org
- xuled.comprehensivewellnesssolutions.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report