SUSPICIOUS — d940e8c6ff8.pdf
SUSPICIOUS — d940e8c6ff8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
04be6e27e36ef495d08e20c20672cc1fda0e580f696adce61844e64e3ccedbf2 - SHA-1:
489008d6bcd82533268bde455e0e2a04849c1d29 - MD5:
adfdb5624f42314cefbee9d1b501f08b - ssdeep:
768:MPgGzpDVfzj9ys6Xn6USJKeJQznp5dyq8HM5nOpXXn+bdAw925:jGFxSX3gKee5kq+MpS3+m625 - TLSH:
T194318EF350D3ED8CBA8BDB13ADB614AA6449D38C60279760459C773D88BC2FD6E41860 - Submitted as: d940e8c6ff8.pdf
- File type: pdf · Size: 40273 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=if-sentences%20mixed%20exercises%20pdf, https://cdn-cms.f-static.net/uploads/4370068/normal_5f8c5c640906b.pdf, https://cdn-cms.f-static.net/uploads/4366620/normal_5f88450b84f3a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=if-sentences%20mixed%20exercises%20pdf
- https://cdn-cms.f-static.net/uploads/4370068/normal_5f8c5c640906b.pdf
- https://cdn-cms.f-static.net/uploads/4366620/normal_5f88450b84f3a.pdf
- https://cdn-cms.f-static.net/uploads/4381091/normal_5f8c31ebeb055.pdf
- https://cdn-cms.f-static.net/uploads/4383698/normal_5f91a39a29f63.pdf
- https://cdn-cms.f-static.net/uploads/4367940/normal_5f8f342c5cd6e.pdf
- https://uploads.strikinglycdn.com/files/acc0b5cb-1ea9-4fce-bf75-88934e427fb0/54447427645.pdf
- https://uploads.strikinglycdn.com/files/cf701ba6-2058-4ae2-a183-1cac216f715f/85498687894.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/4930895.pdf
- https://buximinolid.weebly.com/uploads/1/3/1/3/131381316/sojewisi.pdf
- https://putigazabikikim.weebly.com/uploads/1/3/2/6/132682718/3787719.pdf
- https://uploads.strikinglycdn.com/files/50932f68-a19c-462b-88e2-cb1ac227b34f/77364059143.pdf
- https://uploads.strikinglycdn.com/files/138e1b7d-019e-4d68-a67a-5a5d9bb7d94b/99513321194.pdf
- https://juzukixidud.weebly.com/uploads/1/3/4/4/134453884/tipajuwexunad_dojesa_nuroseta.pdf
- https://wipomozexabezi.weebly.com/uploads/1/3/0/7/130776841/vagazu-safugewetok.pdf
- https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/banixejejuv.pdf
- https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/bepabexobu_xodoxavu_lenusigobu_xadutedid.pdf
- https://uploads.strikinglycdn.com/files/6e45d2fb-f61c-43e8-a1a1-be494fddb849/797284689.pdf
- https://uploads.strikinglycdn.com/files/41b26d5c-b50c-41a5-b334-9459cef287e2/30554104108.pdf
- https://uploads.strikinglycdn.com/files/7eae4785-fbc4-4a41-a1f4-8b592ea45a18/kinabufojenikaxufudix.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- lodirunesu.weebly.com
- buximinolid.weebly.com
- putigazabikikim.weebly.com
- juzukixidud.weebly.com
- wipomozexabezi.weebly.com
- gazesomudari.weebly.com
- fewevivib.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report