SUSPICIOUS — 6c252bf8cdfac.pdf
SUSPICIOUS — 6c252bf8cdfac.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
502e7792adc9b5fdf3117d8c0612f65bf7ab811606c7d7a9cc0ec6f3f6311118 - SHA-1:
7dc7f6d71dbd4ca399083aecf2366f9486737cf1 - MD5:
bec289e92eb1d5f873e9278f9bf19400 - ssdeep:
768:0gGzpD1MOSj8VUQ6fimJ0CVNGIuapV1Px/zKOkiras8jD7eq0TpMZt1btXYyFah4:BGFZMd5p/zKTiOTjeq0TpM1p/FWYkcfX - TLSH:
T1EA328DF74097ED8D7A864B43ADEA125A948ECB4CB236E75084CC632CE4BC4ED7E51850 - Submitted as: 6c252bf8cdfac.pdf
- File type: pdf · Size: 45765 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=types%20of%20acquired%20immunity%20pdf, https://cdn.shopify.com/s/files/1/0268/8299/8449/files/duxewudugomojalagi.pdf, https://cdn.shopify.com/s/files/1/0491/8185/1814/files/king_olaf_verse_puzzle.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=types%20of%20acquired%20immunity%20pdf
- https://cdn.shopify.com/s/files/1/0268/8299/8449/files/duxewudugomojalagi.pdf
- https://cdn.shopify.com/s/files/1/0491/8185/1814/files/king_olaf_verse_puzzle.pdf
- https://cdn.shopify.com/s/files/1/0488/2055/1845/files/26542706603.pdf
- https://cdn.shopify.com/s/files/1/0497/7550/9658/files/anatomy_drawing_books.pdf
- https://cdn.shopify.com/s/files/1/0504/4987/5104/files/29898144549.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/febujuluxe.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/8187236.pdf
- https://wizemeleg.weebly.com/uploads/1/3/4/3/134307012/xawasipewepu_xezorana.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/wusinaje_zeluze_fudakatulizix.pdf
- https://finiluxexolije.weebly.com/uploads/1/3/1/8/131856594/3076176.pdf
- https://xavujome.weebly.com/uploads/1/3/0/7/130739328/3128347.pdf
- https://lajojixuvoporor.weebly.com/uploads/1/3/0/7/130738555/715169.pdf
- https://tibiwurab.weebly.com/uploads/1/3/2/6/132695994/rilik-guwuj-rexosigevipu-mobukumerus.pdf
- https://namunobuwuper.weebly.com/uploads/1/3/0/7/130776476/donepogoruxo-bizaj-kigim-xunap.pdf
- https://cdn-cms.f-static.net/uploads/4378827/normal_5f92004852956.pdf
- https://cdn-cms.f-static.net/uploads/4369152/normal_5f89083da57da.pdf
- https://cdn-cms.f-static.net/uploads/4375518/normal_5f8b2d61ac28a.pdf
- https://cdn-cms.f-static.net/uploads/4374517/normal_5f8a975251fcf.pdf
- https://cdn-cms.f-static.net/uploads/4368958/normal_5f8c83c69dbde.pdf
- https://juzukixidud.weebly.com/uploads/1/3/4/4/134453884/3798389.pdf
- https://xilorufanil.weebly.com/uploads/1/3/0/7/130739938/a0bc8389f.pdf
- https://fopimakalegej.weebly.com/uploads/1/3/0/7/130738542/vimovakiku.pdf
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/fixumadamiwiga_vawefibegegejij.pdf
- https://mamunazeve.weebly.com/uploads/1/3/0/8/130814121/9500420.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- vilukenuxe.weebly.com
- tavumake.weebly.com
- wizemeleg.weebly.com
- lagukekejase.weebly.com
- finiluxexolije.weebly.com
- xavujome.weebly.com
- lajojixuvoporor.weebly.com
- tibiwurab.weebly.com
- namunobuwuper.weebly.com
- cdn-cms.f-static.net
- juzukixidud.weebly.com
- xilorufanil.weebly.com
- fopimakalegej.weebly.com
- xifobosakup.weebly.com
- mamunazeve.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report