SUSPICIOUS — da942785a349.pdf
SUSPICIOUS — da942785a349.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
35655adcc1004dc18f1504978f8036806c29f27d212c549fd27cdc7c26b4a62b - SHA-1:
ed9011624613e12ecc99d4a14c829189b7cdabcc - MD5:
c10a2474f9c86d3ce5e57032d46c0d03 - ssdeep:
768:MgGzpDAploDVTEqc1l4fKjsnh78F68oKZ6TA4/gAz5ZPLOP:JGFUpTYVhIFXMA4/geZSP - TLSH:
T19E318DF300A7ED4C3AC79F4369BA2859914AD78C61239B90559C3A6CC8BC6BD3F01D61 - Submitted as: da942785a349.pdf
- File type: pdf · Size: 40581 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=libro%20el%20feo%20de%20carlos%20cuauhtemoc%20sa, https://cdn-cms.f-static.net/uploads/4365589/normal_5f8717b73d3ef.pdf, https://cdn-cms.f-static.net/uploads/4366022/normal_5f870e09ec1c0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=libro%20el%20feo%20de%20carlos%20cuauhtemoc%20sa
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f8717b73d3ef.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f870e09ec1c0.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f87237aec490.pdf
- https://uploads.strikinglycdn.com/files/b2002340-426a-4a11-a4c6-8e7f12ec210d/tibugazomeb.pdf
- https://uploads.strikinglycdn.com/files/5626c51a-8ee6-4418-9f8e-9a14b96b9481/fumolog.pdf
- https://uploads.strikinglycdn.com/files/a7de5635-183e-4d62-beb4-43149b0ca401/dutifovavonalebedabodov.pdf
- https://uploads.strikinglycdn.com/files/2d84da3e-1563-4961-b6f4-57cbf71f6495/neruzonizolefibalarugopi.pdf
- https://site-1038691.mozfiles.com/files/1038691/62757757583.pdf
- https://site-1042824.mozfiles.com/files/1042824/zuwoxodibiwi.pdf
- https://site-1038783.mozfiles.com/files/1038783/varufubuwajuvawin.pdf
- https://site-1038599.mozfiles.com/files/1038599/50579744685.pdf
- https://site-1037141.mozfiles.com/files/1037141/43246474074.pdf
- https://uploads.strikinglycdn.com/files/6e0d4bbc-b96e-45e2-b15c-f36ec56fc0f9/17039691704.pdf
- https://uploads.strikinglycdn.com/files/aa450e3a-5c14-46c8-80d2-1ef52cc8ecfd/lufetije.pdf
- https://uploads.strikinglycdn.com/files/19f4846f-21c8-4e97-90e7-0bca1b92b94f/kiwetugufisekiv.pdf
- https://uploads.strikinglycdn.com/files/48f782e6-d5a9-4a2a-8e9d-07a011c771ae/ditifubop.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f87289e9c85e.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f86f96cd4331.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038691.mozfiles.com
- site-1042824.mozfiles.com
- site-1038783.mozfiles.com
- site-1038599.mozfiles.com
- site-1037141.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report