SUSPICIOUS — 00c4cc104857.pdf
SUSPICIOUS — 00c4cc104857.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
41125e47a32ee878584faae60478d839fc1bd583d6c874195cfa21102bb5ea6e - SHA-1:
44d03c898ba26a4101c3eee47c39f83c66bd04a1 - MD5:
75a2309dbe03949e87bcfb3b942a7fe1 - ssdeep:
1536:qGFMpPMU4UemJeB7q1V8s/OtOCRZ6Cdcm:TFMpzIW11uRZ6Cn - TLSH:
T17834B0F365D7EC8CB986EB136D5B156960C9C388A23AD760588C776CC4BC2BDBE00560 - Submitted as: 00c4cc104857.pdf
- File type: pdf · Size: 56164 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=auto%20reverse%204shared, https://cdn-cms.f-static.net/uploads/4365525/normal_5f872695e1dd6.pdf, https://cdn-cms.f-static.net/uploads/4365562/normal_5f872184819c2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=auto%20reverse%204shared
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f872695e1dd6.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f872184819c2.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f872caed6830.pdf
- https://site-1038890.mozfiles.com/files/1038890/liwomozovabubefa.pdf
- https://site-1037261.mozfiles.com/files/1037261/bizili.pdf
- https://site-1039556.mozfiles.com/files/1039556/74836215861.pdf
- https://site-1039639.mozfiles.com/files/1039639/31727791908.pdf
- https://site-1038820.mozfiles.com/files/1038820/suduguwanufeweg.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/winepogor.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/8767144.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/8ba85efefb.pdf
- https://gituwere.weebly.com/uploads/1/3/0/7/130740556/1562145.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/fe19c4.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/6792893.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f8735d8ef8ec.pdf
- https://cdn-cms.f-static.net/uploads/4367905/normal_5f87564643cd5.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f8716cd54e8f.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f8703e0d38f7.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f871d690523b.pdf
- https://uploads.strikinglycdn.com/files/53ba27c1-2bff-4d2f-8717-4dc0afe89d3e/fatufaxisanupa.pdf
- https://uploads.strikinglycdn.com/files/41c7d744-747d-4456-95e0-57ec0f7375b7/60353335127.pdf
- https://uploads.strikinglycdn.com/files/bd2fb088-d7d9-4eee-90d4-036f92779b53/21846765867.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1038890.mozfiles.com
- site-1037261.mozfiles.com
- site-1039556.mozfiles.com
- site-1039639.mozfiles.com
- site-1038820.mozfiles.com
- zoxuzuxebexot.weebly.com
- dimaxafazeza.weebly.com
- jatorogerujew.weebly.com
- xojerajap.weebly.com
- gituwere.weebly.com
- boguvetasitob.weebly.com
- rabifupokuwu.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report