SUSPICIOUS — 116cfc197.pdf
SUSPICIOUS — 116cfc197.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4e0ea2b11967b29ea2c214ca43be8ed3dca1b254dfcbfb3fdfc5e3c74a3f4ab3 - SHA-1:
55854b20688fa8d1d3098cb31a08fb2869e94252 - MD5:
6e493cf9327ec9e5edb63136167a8041 - ssdeep:
768:qgGzpDXWr8WjAuz5Uohz+6wZeFeYlAy83Ecawj:3GFzs+ohz+6wZ6eaAvDj - TLSH:
T1462F9EF351A3ED8C3A86AB13EDE6114A914AC64C2033A7B054DD7B7CC8BC6BC6D44961 - Submitted as: 116cfc197.pdf
- File type: pdf · Size: 33304 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=cpm%20math%20textbook%20login, https://uploads.strikinglycdn.com/files/02304743-5137-4082-96bb-bb6e2b6581b1/tajomewuw.pdf, https://mesovozilepako.weebly.com/uploads/1/3/4/5/134588792/2279936.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=cpm%20math%20textbook%20login
- https://s3.amazonaws.com/zuwimadaneb/hill_climb_racing_2_money_apk.pdf
- https://uploads.strikinglycdn.com/files/02304743-5137-4082-96bb-bb6e2b6581b1/tajomewuw.pdf
- https://saridejawe.files.wordpress.com/2020/11/rotido.pdf
- https://witukam.files.wordpress.com/2020/11/lalifozekuwivodikofufaz.pdf
- https://s3.amazonaws.com/fidefofudi/amazon_in_2017_case_study.pdf
- https://notazit.files.wordpress.com/2020/11/official_letter_writing_skills.pdf
- https://mesovozilepako.weebly.com/uploads/1/3/4/5/134588792/2279936.pdf
- https://s3.amazonaws.com/sazixipame/new_cutting_edge_intermediate_answer_key.pdf
- https://s3.amazonaws.com/rewepalazamiso/72106603185.pdf
- https://jubonofu.weebly.com/uploads/1/3/4/2/134234671/4234771.pdf
- https://uploads.strikinglycdn.com/files/a2642a5e-b7df-4dcc-84f3-3197a07396c8/11432951848.pdf
- https://uploads.strikinglycdn.com/files/e4b880aa-21d5-4e83-b6bd-2e7f4c25e250/92343999769.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- saridejawe.files.wordpress.com
- witukam.files.wordpress.com
- notazit.files.wordpress.com
- mesovozilepako.weebly.com
- jubonofu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report