SUSPICIOUS — d415b.pdf
SUSPICIOUS — d415b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3906585ded95a06eac07228c5d8e73be0f051d0ea2a3f769ea75c0228de319e9 - SHA-1:
9cea67c9f72d810016d66cbc17c03487cae1cd71 - MD5:
cb21513cabf0ddedeb5f075f1096443e - ssdeep:
768:PsSgGzpDqpl1XCeZlt2jglZvDw5y+5MLpjXxBHE6OIy8PMwmhz/EOeH9eSdwhLO:PsPGFmpPXr2y+5MLxXftC8PMwQz/XQeG - TLSH:
T1D9329EF31093ED9C7A8B5F136AAA119DA18BC388A137D690548C772CC47CAED7F01960 - Submitted as: d415b.pdf
- File type: pdf · Size: 43496 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=how%20to%20make%20a%20csgo%20skin, https://uploads.strikinglycdn.com/files/8d6c5bd4-abd2-45e0-b344-542cdfa2888c/kuresilem.pdf, https://uploads.strikinglycdn.com/files/460152cf-cb39-4259-89bd-f04eb888198b/life_the_science_of_biology.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=how%20to%20make%20a%20csgo%20skin
- https://uploads.strikinglycdn.com/files/8d6c5bd4-abd2-45e0-b344-542cdfa2888c/kuresilem.pdf
- https://uploads.strikinglycdn.com/files/460152cf-cb39-4259-89bd-f04eb888198b/life_the_science_of_biology.pdf
- https://uploads.strikinglycdn.com/files/5566668b-d149-4ec9-8b99-1b47dc532d53/filaxasigimupugi.pdf
- https://uploads.strikinglycdn.com/files/4ae5dc90-4ec0-45af-aa57-f315fb9bba01/99485188375.pdf
- https://sakukavazu.weebly.com/uploads/1/3/1/3/131379729/58bf77443b1cb.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/ee2cd8d0dd2.pdf
- https://jikeberu.weebly.com/uploads/1/3/1/8/131857846/pererasunob_bixawuzapag_latikopu.pdf
- https://mojenosude.weebly.com/uploads/1/3/1/3/131382274/nolukida-wewiwasuf-kebori-dejev.pdf
- https://cdn-cms.f-static.net/uploads/4367959/normal_5f8b253c9bca1.pdf
- https://cdn-cms.f-static.net/uploads/4374024/normal_5f8c3bed57c16.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87165aa2b8c.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f870a2c8fcf7.pdf
- https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/narodewavuzekom_xivatiketavas.pdf
- https://mogidudurunupiz.weebly.com/uploads/1/3/2/6/132695636/wamemewewu.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f879b02ac7d8.pdf
- https://cdn-cms.f-static.net/uploads/4368505/normal_5f87c12a055c7.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f87012c147a7.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f87b70b66ac5.pdf
- https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/kemevolesuwi_gidaxegapifi_boladetiji.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/4aab8938.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- sakukavazu.weebly.com
- damijuvik.weebly.com
- jikeberu.weebly.com
- mojenosude.weebly.com
- cdn-cms.f-static.net
- kokubexajaluk.weebly.com
- mogidudurunupiz.weebly.com
- naxesitigas.weebly.com
- papunagaku.weebly.com
- www.elle.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report