SUSPICIOUS — 515ae0caa.pdf
SUSPICIOUS — 515ae0caa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3c92d0d5aa8a19f22b80cdedaaaa1d5dd22fff27006ac0324a0a7195fbb53038 - SHA-1:
7055659b047aa5e6bcc6398fef738ab228cd66f6 - MD5:
0dde97b524e06110db6d807ef0c612c3 - ssdeep:
768:mgGzpDkIRAzfRCX9PcY8gpU1bjukLVTcvyV3ZZGV9/hF9V1Ksipnx+0dglsqX:zGFIctq2U1vukLJ/HGp9id80OlsqX - TLSH:
T14B31AEF34597DE8C7A9A4B473DB61499648AE388A0235A3404DC7B7DC4BCBBD7E50820 - Submitted as: 515ae0caa.pdf
- File type: pdf · Size: 41843 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafffe.ru/wb?keyword=naming%20points%20lines%20and%20planes%20worksheet%20pdf, https://uploads.strikinglycdn.com/files/2cd5f04a-1421-4b02-8914-26ffa6182c7e/ruzoguwufamakitim.pdf, https://mabudorowux.weebly.com/uploads/1/3/4/4/134458492/1ceb31eb6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=naming%20points%20lines%20and%20planes%20worksheet%20pdf
- https://uploads.strikinglycdn.com/files/2cd5f04a-1421-4b02-8914-26ffa6182c7e/ruzoguwufamakitim.pdf
- https://mabudorowux.weebly.com/uploads/1/3/4/4/134458492/1ceb31eb6.pdf
- https://cdn-cms.f-static.net/uploads/4366637/normal_5f8f6e6635778.pdf
- https://uploads.strikinglycdn.com/files/f2667b00-d6a7-453a-bc6b-0ec85b1edbef/topenidikekiwobefome.pdf
- https://vifaniju.weebly.com/uploads/1/3/4/5/134507083/7106893.pdf
- https://cdn-cms.f-static.net/uploads/4387929/normal_5f8d2744f0d0a.pdf
- https://gipavibipo.weebly.com/uploads/1/3/4/6/134654588/wugurerupepagu.pdf
- https://zujuvigewif.files.wordpress.com/2020/11/sociedad_en_nombre_colectivo_mexico.pdf
- https://pazeden.files.wordpress.com/2020/11/86767518253.pdf
- https://uploads.strikinglycdn.com/files/31a990db-ec9a-495f-a077-29ed9d4d97f8/74057662537.pdf
- https://cdn-cms.f-static.net/uploads/4368748/normal_5f993aef12150.pdf
- https://uploads.strikinglycdn.com/files/9f80c93c-8e4d-4ab1-a0a5-57bab8f1292b/89343294466.pdf
- https://fegaretu.files.wordpress.com/2020/11/gesetisamisovubabaxavidum.pdf
- https://vunixumo.weebly.com/uploads/1/3/1/4/131453253/fosofep_rupox.pdf
- https://kovumagamu.weebly.com/uploads/1/3/4/5/134578336/bijimuduzubap_nefisabono.pdf
- https://niragadofob.files.wordpress.com/2020/11/31700805951.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- uploads.strikinglycdn.com
- mabudorowux.weebly.com
- cdn-cms.f-static.net
- vifaniju.weebly.com
- gipavibipo.weebly.com
- zujuvigewif.files.wordpress.com
- pazeden.files.wordpress.com
- fegaretu.files.wordpress.com
- vunixumo.weebly.com
- kovumagamu.weebly.com
- niragadofob.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report