SUSPICIOUS — cfff6.pdf
SUSPICIOUS — cfff6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
1d556bcee26a9d38c06849398058e9519dced8d30426c51eef88b13140d23a72 - SHA-1:
703f7621cdbe2ba7795ac423d8d61e191e32f5a3 - MD5:
bad1fbfb11c72c8ae25da8bece410346 - ssdeep:
768:VgGzpDpvpg7wVXJD37/qR6MPIYdvbdCFbudd2Q0uBU0/04GBO:GGFVvprA6Mwkvbdkwd2QZBUf4GBO - TLSH:
T138327DF300A7EE4C76C75B53AEEA268D6049D78C6132A7604588772CD1BC3AE7F10961 - Submitted as: cfff6.pdf
- File type: pdf · Size: 47192 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=longman%20introductory%20course%20for%20the, https://site-1041301.mozfiles.com/files/1041301/guxofikobuf.pdf, https://site-1043295.mozfiles.com/files/1043295/bipugataropugenufetaxe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=longman%20introductory%20course%20for%20the
- https://site-1041301.mozfiles.com/files/1041301/guxofikobuf.pdf
- https://site-1043295.mozfiles.com/files/1043295/bipugataropugenufetaxe.pdf
- https://site-1042556.mozfiles.com/files/1042556/42257505971.pdf
- https://uploads.strikinglycdn.com/files/c84ac92a-fa02-48c9-8412-9ce716d8647c/83346033876.pdf
- https://uploads.strikinglycdn.com/files/895cb3ad-b5b8-4259-930e-bc749161d40f/sebedizarorogidonerexixuz.pdf
- https://uploads.strikinglycdn.com/files/77557ca9-5ba0-41f2-8940-5a71bc765e2f/74728497966.pdf
- https://uploads.strikinglycdn.com/files/8eb07043-6cf1-4066-9736-72d0e9c62533/resavav.pdf
- https://uploads.strikinglycdn.com/files/aaf2a048-9419-49ae-9d44-c5a3a76472dd/33530883977.pdf
- https://cdn.shopify.com/s/files/1/0478/6716/6886/files/bekefinaretinokexubexo.pdf
- https://cdn.shopify.com/s/files/1/0497/1842/7809/files/rom_games_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0497/9356/4833/files/80571749455.pdf
- https://cdn.shopify.com/s/files/1/0498/4517/4439/files/sisejasizexeka.pdf
- https://cdn.shopify.com/s/files/1/0266/9042/0921/files/basketball_heads_games.pdf
- https://site-1036724.mozfiles.com/files/1036724/57096439385.pdf
- https://site-1041281.mozfiles.com/files/1041281/27683613357.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/4041939.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/godekux.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/tuwobidudaxot_kuvoxa_livosejatat_rafedegoruf.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/05209.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3731638.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/gegakunagakamet-wipumidujo.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- site-1041301.mozfiles.com
- site-1043295.mozfiles.com
- site-1042556.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1036724.mozfiles.com
- site-1041281.mozfiles.com
- bedizegoresupa.weebly.com
- jakedekokobara.weebly.com
- jeponiruwapin.weebly.com
- rezizeme.weebly.com
- gimejexoxixaza.weebly.com
- walijogopabo.weebly.com
- narogigadi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report