SUSPICIOUS — eed8573b.pdf
SUSPICIOUS — eed8573b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3abf0d285bac8b4848f285fe840d42a3998b5922c185e713d0795fb552861d6c - SHA-1:
50d3cb8d63f8f916b8ac84c270b1747b9d59df4c - MD5:
73cdc3fb018fa05ecd09d6eb43bb7035 - ssdeep:
768:VgGzpDUpwWM2mcdzTu9dZarBaqhSx7iYEtSseK7e5N7BDKx8B0mQlReTpydI9:GGFYpRzTq+YNObt4DKKB0mQ/dI9 - TLSH:
T1E3349EF750A3EC8C798BDF17ADBB108A904A8B4D60379F900588762CD4BC6FE6E41951 - Submitted as: eed8573b.pdf
- File type: pdf · Size: 54981 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=act%20reading%20practice%20test%20with%20answer%20key, https://cdn-cms.f-static.net/uploads/4365586/normal_5f872a6d746da.pdf, https://cdn-cms.f-static.net/uploads/4366004/normal_5f8701b339f93.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=act%20reading%20practice%20test%20with%20answer%20key
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f872a6d746da.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f8701b339f93.pdf
- https://cdn-cms.f-static.net/uploads/4367656/normal_5f8787df60155.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f870ae861a0d.pdf
- https://uploads.strikinglycdn.com/files/d28d2748-9255-4646-994c-7e5cece1d520/xeworutanetulexevigux.pdf
- https://uploads.strikinglycdn.com/files/03766e83-c5e7-4bb0-be58-56a01b7e3429/kuzidesifosemajir.pdf
- https://uploads.strikinglycdn.com/files/2def5042-5c41-4606-9779-7dbb280bcc91/67254895197.pdf
- https://uploads.strikinglycdn.com/files/36348af1-bcce-48d5-a5d1-1e29aaed80f2/29348508496.pdf
- https://site-1038739.mozfiles.com/files/1038739/sedekenobopaxav.pdf
- https://site-1040879.mozfiles.com/files/1040879/tunopebup.pdf
- https://site-1039316.mozfiles.com/files/1039316/1842307078.pdf
- https://cdn.shopify.com/s/files/1/0428/6208/4262/files/judge_eileen_rakower_part_rules.pdf
- https://cdn.shopify.com/s/files/1/0428/9101/8396/files/kenmore_ultra_wash_dishwasher_model_665_service_manual.pdf
- https://cdn.shopify.com/s/files/1/0496/7215/9395/files/forte_piano_contrasts_and_echo_effects_are_typical_in_the_music_of_the.pdf
- https://cdn.shopify.com/s/files/1/0434/3191/9765/files/99672872468.pdf
- https://cdn.shopify.com/s/files/1/0482/0185/9224/files/olympus_om2_vs_om2n.pdf
- https://gonerogad.weebly.com/uploads/1/3/1/4/131438616/2773308.pdf
- https://sonilotosoj.weebly.com/uploads/1/3/1/3/131379329/voxexawarireku_jujumide.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/bibebozonitenerox.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/ligoxeloterewubim.pdf
- https://rozolabo.weebly.com/uploads/1/3/0/8/130814594/c210c2179d3.pdf
- https://zoxaminajoge.weebly.com/uploads/1/3/1/6/131637873/9544597.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3532345.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/vazefobizesekewe.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038739.mozfiles.com
- site-1040879.mozfiles.com
- site-1039316.mozfiles.com
- cdn.shopify.com
- gonerogad.weebly.com
- sonilotosoj.weebly.com
- viweposedijul.weebly.com
- jufaxexave.weebly.com
- rozolabo.weebly.com
- zoxaminajoge.weebly.com
- zoxuzuxebexot.weebly.com
- tavumake.weebly.com
- vozunutav.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report