SUSPICIOUS — f63a11f6e66d70c.pdf
SUSPICIOUS — f63a11f6e66d70c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
192a005b4f057cdfceba3a140bd8064d5dc2c925d94e8ac14e257770a6bfe254 - SHA-1:
6aea3afb45baac8f7b4f4916b04822ab6bc4bd40 - MD5:
d824d3009558bd1f2a278bc9416316d6 - ssdeep:
1536:vGFOeK0rda67l4IvvbaDDq7MqBP/VeQt2:eFOeK0Ra1Dq7Mw3MR - TLSH:
T18435C0F31597ED8C7A8ABB03ADFA0198118AD788313297A064C8762CC57C6FD7D10E61 - Submitted as: f63a11f6e66d70c.pdf
- File type: pdf · Size: 60031 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=don, https://uploads.strikinglycdn.com/files/b90674be-9dc7-4abe-beb7-ece05431c98a/28194296244.pdf, https://uploads.strikinglycdn.com/files/458e5385-de72-47bc-8706-c703a583a861/36248984515.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=don
- https://uploads.strikinglycdn.com/files/b90674be-9dc7-4abe-beb7-ece05431c98a/28194296244.pdf
- https://uploads.strikinglycdn.com/files/458e5385-de72-47bc-8706-c703a583a861/36248984515.pdf
- https://uploads.strikinglycdn.com/files/e3a7a7b8-4e52-4780-9210-8df1d207b118/jifetebutedomumumakibonu.pdf
- https://uploads.strikinglycdn.com/files/83bb2f8e-806d-4530-99b5-3f6612c4c202/kezotuxezebov.pdf
- https://uploads.strikinglycdn.com/files/d01f7c44-ba98-46b3-8621-b309b2b56b16/86601250735.pdf
- https://uploads.strikinglycdn.com/files/a063c47e-4aca-4daf-b05b-7d6e4243b9b1/37241355890.pdf
- https://uploads.strikinglycdn.com/files/962781bd-d3c6-4539-ac42-b27842c44fad/53830914689.pdf
- https://nurekagenarufab.weebly.com/uploads/1/3/1/6/131636906/876888.pdf
- https://mixorone.weebly.com/uploads/1/3/1/4/131438240/vinon.pdf
- https://jumuwubugunitus.weebly.com/uploads/1/3/1/0/131070493/zebopimopu-pupuxelolux-rorigolepum.pdf
- https://uploads.strikinglycdn.com/files/a93d0556-ae59-44ec-aed0-5cf5875c59c0/loduretetetavogapoke.pdf
- https://uploads.strikinglycdn.com/files/1b663193-693d-4223-96a9-1703a2c18dc7/luxativatanasuzala.pdf
- https://uploads.strikinglycdn.com/files/8a7d7a95-4582-4433-8f65-57262073406a/12765214097.pdf
- https://uploads.strikinglycdn.com/files/f958a6bd-009b-4e9c-8a8f-954a1b1513dd/diferencias_entre_fabulas_y_refranes.pdf
- https://uploads.strikinglycdn.com/files/e2a4a327-4e62-4cc7-9197-6e68245b947e/tosagemafenidojuwub.pdf
- https://cdn.shopify.com/s/files/1/0480/6046/5316/files/gekodigomebotujujo.pdf
- https://cdn.shopify.com/s/files/1/0438/6134/4406/files/baranetadudodapagenesaj.pdf
- https://cdn.shopify.com/s/files/1/0431/2891/4087/files/dafirosapevegodezeso.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- nurekagenarufab.weebly.com
- mixorone.weebly.com
- jumuwubugunitus.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report