SUSPICIOUS — 0c5621b.pdf
SUSPICIOUS — 0c5621b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
058903a201fd6a1f989d0507eb6f2cc561692b7175238351d21b249afcdb4ad9 - SHA-1:
57082f0a08119ad9fb766fddd26d002c9816f128 - MD5:
fb3d3d7e9c098a0adfd7ca20927151a7 - ssdeep:
3072:lFv1e42FLIZaaSipPplJ/HEicYv4sNHKC3GB97Y:rvMZ2QFwJ/EiVAsAGwe - TLSH:
T16F3BE1F31497DD0EAB8E8F13EC630599714AE28C2222E7E445587A6CC5BD27CBF02951 - Submitted as: 0c5621b.pdf
- File type: pdf · Size: 109562 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=%25D9%2585%25D9%2584%25D8%25AD%25D9%2585%25D8%25A9%20%25D8%25AC%25D9%2584%25D8%25AC%25D8%25A7%25D9%2585%25D8%25B4%20%25D9%2588%25D8%25A7%25D9%2584%25D9%2586%25D8%25B5%20%25D8%25A7%25D9%2584%25D9%2582%25D8%25B1%25D8%25A2%25D9%2586%25D9%258A%20pdf, https://cdn.shopify.com/s/files/1/0431/3881/0023/files/cats_in_the_cradle_lyrics.pdf, https://cdn.shopify.com/s/files/1/0481/5460/7777/files/cartas_del_diablo_a_su_sobrino_libro_completo_gratis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=%25D9%2585%25D9%2584%25D8%25AD%25D9%2585%25D8%25A9%20%25D8%25AC%25D9%2584%25D8%25AC%25D8%25A7%25D9%2585%25D8%25B4%20%25D9%2588%25D8%25A7%25D9%2584%25D9%2586%25D8%25B5%20%25D8%25A7%25D9%2584%25D9%2582%25D8%25B1%25D8%25A2%25D9%2586%25D9%258A%20pdf
- https://cdn.shopify.com/s/files/1/0431/3881/0023/files/cats_in_the_cradle_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0481/5460/7777/files/cartas_del_diablo_a_su_sobrino_libro_completo_gratis.pdf
- https://cdn.shopify.com/s/files/1/0484/0721/6285/files/32392443844.pdf
- https://cdn.shopify.com/s/files/1/0432/8531/5744/files/juniper_default_password_root.pdf
- https://cdn.shopify.com/s/files/1/0496/7035/7149/files/google_finance_cryptocurrency.pdf
- https://uploads.strikinglycdn.com/files/effe6820-bc48-453e-b77b-0c0e75f47a97/janeduj.pdf
- https://uploads.strikinglycdn.com/files/f8dd1645-3b08-439d-96a8-d9a2cf320504/85173166769.pdf
- https://uploads.strikinglycdn.com/files/adf9b33d-3600-4cd4-9dcc-2ec17ce5037a/vaxokerivokiveselamo.pdf
- https://uploads.strikinglycdn.com/files/8559ceba-c2f5-42ac-b7df-d2593bb02b20/51111703074.pdf
- https://uploads.strikinglycdn.com/files/31f1e771-8ef5-4999-938b-b19e13b6eaf0/luxuteruwug.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/zifitam.pdf
- https://kidunaxu.weebly.com/uploads/1/3/1/4/131437100/dulefipalep_jobowajoxugo_wiribulelom_nuzigo.pdf
- https://site-1038782.mozfiles.com/files/1038782/20649752066.pdf
- https://site-1042545.mozfiles.com/files/1042545/jawolozapivog.pdf
- https://site-1043646.mozfiles.com/files/1043646/the_inheritance_cycle_series_download.pdf
- https://uploads.strikinglycdn.com/files/12761282-db7c-4d50-97b6-e3c1e3da9cf8/jakosusekanimeli.pdf
- https://uploads.strikinglycdn.com/files/3814d2ec-199d-486a-ab9f-48f9c4a5cb9f/pubosapo.pdf
- https://cdn.shopify.com/s/files/1/0485/0057/2315/files/dinazamupamuvatadamikavuw.pdf
- https://cdn.shopify.com/s/files/1/0434/4283/1522/files/matt_pelissier_nh.pdf
- https://cdn.shopify.com/s/files/1/0498/2915/0875/files/what_darwin_never_knew_worksheet_answer_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- zoveponezewuda.weebly.com
- kidunaxu.weebly.com
- site-1038782.mozfiles.com
- site-1042545.mozfiles.com
- site-1043646.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report