SUSPICIOUS — 5767677.pdf
SUSPICIOUS — 5767677.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
263d6f0fa9febb6caba0d25b595253c7e84052778aabb37c04d965944c6f5366 - SHA-1:
fa6fe50caa99e8cb45be592eeb3f0ddef2751701 - MD5:
a08644a7fd3d321c3ea153d731c43bf1 - ssdeep:
768:ogGzpDceg2UDqXyEYiZ5GEPIPP+iIOBzJHFlBA6Hpq7FWXlPWzAExr:lGF4e2IOBzJHFly6HpIF4lPAAExr - TLSH:
T137306CF31097EE4D7A8BAB935CA71259614AC3887236979049CCBB2CC4BC1BD7F10911 - Submitted as: 5767677.pdf
- File type: pdf · Size: 39226 bytes
- Verdict: suspicious (35/100)
Detections (1 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=schema%20raccordement%20cuve%20fioul, https://cdn-cms.f-static.net/uploads/4365619/normal_5f86f86516bc1.pdf, https://cdn-cms.f-static.net/uploads/4369512/normal_5f8ace6f4ca95.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=schema%20raccordement%20cuve%20fioul
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f86f86516bc1.pdf
- https://cdn-cms.f-static.net/uploads/4369512/normal_5f8ace6f4ca95.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f872db330c3b.pdf
- https://cdn-cms.f-static.net/uploads/4372101/normal_5f89e91b4d8df.pdf
- https://cdn-cms.f-static.net/uploads/4368768/normal_5f8af9917bcff.pdf
- https://uploads.strikinglycdn.com/files/142573c7-506c-4d47-ba6c-fbe6cc319d86/18696903616.pdf
- https://uploads.strikinglycdn.com/files/c020cf8f-b865-4687-9e70-0a1af7575c1c/lejadalunuzokubenizosu.pdf
- https://uploads.strikinglycdn.com/files/f60137c1-c10c-454d-983d-acaaccd4e80c/jebexesowor.pdf
- https://uploads.strikinglycdn.com/files/cec708a9-3886-4539-9344-1752b4a68910/50161029207.pdf
- https://uploads.strikinglycdn.com/files/02ad3977-d253-45c8-bed0-4aece6573915/mifomagazuzofobetejew.pdf
- https://uploads.strikinglycdn.com/files/24a13083-92b6-41e9-8bf2-efac1463bc9a/51956683302.pdf
- https://fimozafovobas.weebly.com/uploads/1/3/2/7/132741130/nozupemeregatililu.pdf
- https://faworufobideped.weebly.com/uploads/1/3/2/6/132682851/gizoredonikojin.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/6023986.pdf
- https://firedisivimi.weebly.com/uploads/1/3/0/9/130969818/tetevewutizevis_zofanabebadavu.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f8755935d104.pdf
- https://cdn-cms.f-static.net/uploads/4383300/normal_5f8c901485564.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f8d63c0895da.pdf
- https://cdn-cms.f-static.net/uploads/4375195/normal_5f8c53cd90dde.pdf
- https://cdn-cms.f-static.net/uploads/4367303/normal_5f874750c7098.pdf
- https://cdn-cms.f-static.net/uploads/4369645/normal_5f8b37e96ba43.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f880b7641b6e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- fimozafovobas.weebly.com
- faworufobideped.weebly.com
- genigudepa.weebly.com
- firedisivimi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report