SUSPICIOUS — f91cf1_a2e1902e21ac4be88024b48c92a35c0e.pdf
SUSPICIOUS — f91cf1_a2e1902e21ac4be88024b48c92a35c0e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 1 of 49 detection engines flagged it.
Identification
- SHA-256:
070cb2096827c6ed095b5e1236c304def08b8bfe1ce66ae43d5682b0911f4f23 - SHA-1:
d6b3cda66a4805ec4633da09aacfcb639a68ee8e - MD5:
d6e006b446024db18856ce7563505720 - ssdeep:
768:vgGzpDGcw++5TsrM1FfhfO1Hk/x2GWTkP51qihT0:YGFScwQra9OdkAGl50ihT0 - TLSH:
T13E319EF390EBEC4C2A8AAB03BDB510986086D64C6235A76458D9777CC5BC6BC6F10D30 - Submitted as: f91cf1_a2e1902e21ac4be88024b48c92a35c0e.pdf
- File type: pdf · Size: 42784 bytes
- Verdict: suspicious (44/100)
Detections (1 of 49 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/wix?keyword=e30+manual+transmission+oil, http://fezezogim.cambridgesupervisiontraining.org/uploads/1/3/2/6/132681337/divef.pdf, http://febezo.melissaaltamirano.com/uploads/1/3/1/4/131438741/2984980.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/wix?keyword=e30+manual+transmission+oil
- http://fezezogim.cambridgesupervisiontraining.org/uploads/1/3/2/6/132681337/divef.pdf
- http://febezo.melissaaltamirano.com/uploads/1/3/1/4/131438741/2984980.pdf
- http://files.breastfeedinghousecalls.com/uploads/1/3/2/8/132815008/bilini-kejazekoruj.pdf
- http://gupel.lexieslittlebearschildcare.com/uploads/1/3/2/3/132302782/ef364613685ecc.pdf
- http://files.catastrophantastic.com/uploads/1/3/1/8/131858108/dozakapejafaw_pesasulodadabuv_zifibaz_dafajero.pdf
- http://tupit.huddersfieldartsociety.com/uploads/1/3/0/9/130969153/turisonijeseta.pdf
- http://files.vossyogaandbodywork.com/uploads/1/3/1/6/131606876/regikugafesuti-kuledabez-sofiwuwozowidab-miwotu.pdf
- https://f6c366fc-f807-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/d775a9_904bc3f8fc494568b564d372cb15ead6.pdf?index=true
- https://0926e3a0-f808-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/1ebe14_d10aaf0ceaad42ae8d1c3346495c1d27.pdf?index=true
- https://028f61b6-f808-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/fd4c29_ea0b973a3d7b48e0a8a7cf27a6255490.pdf?index=true
- https://200cbb3a-f808-11ea-a328-fc4dd43d38a6.filesusr.com/ugd/fd4c29_f8822443eeda4fc98dff82760e6ff4bd.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- fezezogim.cambridgesupervisiontraining.org
- febezo.melissaaltamirano.com
- files.breastfeedinghousecalls.com
- gupel.lexieslittlebearschildcare.com
- files.catastrophantastic.com
- tupit.huddersfieldartsociety.com
- files.vossyogaandbodywork.com
- f6c366fc-f807-11ea-a328-fc4dd43d38a6.filesusr.com
- 0926e3a0-f808-11ea-a328-fc4dd43d38a6.filesusr.com
- 028f61b6-f808-11ea-a328-fc4dd43d38a6.filesusr.com
- 200cbb3a-f808-11ea-a328-fc4dd43d38a6.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report