SUSPICIOUS — dafb0942e6e5a.pdf
SUSPICIOUS — dafb0942e6e5a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
3c0a5e94b25bc23b57816dbac9d3a8fa859e0187ac205e9c077862a292e0b0d5 - SHA-1:
a13b6d604b3cb10912cb31dc9e33f1664531cb9b - MD5:
a0328868de8ff161a7920708a1075937 - ssdeep:
768:QgGzpD2t0sdZIxIwAIv+n/Y6BRvPGMI2Q/UGGKC45NPGMylw4:9GFSaIuaNvPG+pGGlyPGMylw4 - TLSH:
T11F31AFF351ABDC4D3B87AB0B6EF204582146C64C7137E6B018E8776DC4B8A7C2D519A1 - Submitted as: dafb0942e6e5a.pdf
- File type: pdf · Size: 41547 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=manual%20d%20duct%20design%20software, https://uploads.strikinglycdn.com/files/f9035687-ed09-4475-8847-b925ad8413ef/69649596879.pdf, https://uploads.strikinglycdn.com/files/c6f8d7c4-d1da-47a3-82ce-3f892feff9d2/32282254065.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=manual%20d%20duct%20design%20software
- https://s3.amazonaws.com/purufiz/manufactured_goods_in_the_midwest_region.pdf
- https://uploads.strikinglycdn.com/files/f9035687-ed09-4475-8847-b925ad8413ef/69649596879.pdf
- https://uploads.strikinglycdn.com/files/c6f8d7c4-d1da-47a3-82ce-3f892feff9d2/32282254065.pdf
- https://cdn-cms.f-static.net/uploads/4368762/normal_5f87890ca038f.pdf
- https://uploads.strikinglycdn.com/files/8a69358a-7913-48cc-837c-ec51bc1dd8b3/11062054356.pdf
- https://s3.amazonaws.com/jamokaroxoj/nipukejakaguzaxepupiju.pdf
- https://uploads.strikinglycdn.com/files/34956bb0-3bbb-4d4a-9000-c9b2164e9357/mixudumak.pdf
- https://s3.amazonaws.com/subud/bodyweight_exercise_program.pdf
- https://uploads.strikinglycdn.com/files/d1e2481c-40d8-4ec0-9f69-b968edae33fd/81575927861.pdf
- https://cdn-cms.f-static.net/uploads/4370299/normal_5f899caf85c07.pdf
- https://s3.amazonaws.com/gedimuta/73314996180.pdf
- https://uploads.strikinglycdn.com/files/bdeba061-62e4-4780-acf8-192fa01bd736/susuzifebajumozibipuzodot.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report