SUSPICIOUS — cbb08f94.pdf
SUSPICIOUS — cbb08f94.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
52af6972bc88f4aeeaa0a2aa568de8f97ed51d7abacf4d7005ba7549bdee9804 - SHA-1:
8cf54ff1f11abaa6a205680b24e00577f337be82 - MD5:
b827f17da8d921327243be4d720b1b78 - ssdeep:
768:WgGzpDKpjgU44uAfubghHhJI+V1qSYc8FdTvzm5wE9XsC+zi7y:DGF2pebg++j98F1mWEGCOi7y - TLSH:
T1A3305BF30197DD8C7A87AB83BCB71594548AC28862379760189C7B6DC4BC5BD7F40960 - Submitted as: cbb08f94.pdf
- File type: pdf · Size: 37010 bytes
- Verdict: suspicious (35/100)
Detections (1 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=arist%C3%B3teles%20pol%C3%ADtica%20gredos, https://cdn.shopify.com/s/files/1/0493/6453/3414/files/knights_and_dragons_hack_iosgods.pdf, https://cdn.shopify.com/s/files/1/0432/6457/3593/files/honda_lawn_mower_manual_hrx217.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=arist%C3%B3teles%20pol%C3%ADtica%20gredos
- https://cdn.shopify.com/s/files/1/0493/6453/3414/files/knights_and_dragons_hack_iosgods.pdf
- https://cdn.shopify.com/s/files/1/0432/6457/3593/files/honda_lawn_mower_manual_hrx217.pdf
- https://cdn.shopify.com/s/files/1/0479/2523/1772/files/10613798893.pdf
- https://cdn.shopify.com/s/files/1/0492/5485/8908/files/littlejohn_elementary_school_dekalb_illinois.pdf
- https://cdn.shopify.com/s/files/1/0429/3482/9222/files/45761653012.pdf
- https://uploads.strikinglycdn.com/files/41b634b8-05dc-43d4-8eba-821d1f544f2c/19524689391.pdf
- https://uploads.strikinglycdn.com/files/4f560379-5f51-4f1e-aff6-6e14bc701120/11727874186.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/e276efd25922.pdf
- https://jikolugoxolij.weebly.com/uploads/1/3/1/3/131379047/5ee3b0f8.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/a0cb48.pdf
- https://netulomite.weebly.com/uploads/1/3/2/8/132814473/wuzozudezepepemuj.pdf
- https://uploads.strikinglycdn.com/files/9f9cc328-dc18-4601-a676-207d21608bd2/kozinawuxezojivetozolod.pdf
- https://uploads.strikinglycdn.com/files/f668c451-6eee-4cf0-83e1-7a70245a816a/fejera.pdf
- https://uploads.strikinglycdn.com/files/3d9fcfc2-084d-40d0-978a-e49452eaf909/41814580875.pdf
- https://uploads.strikinglycdn.com/files/7d2f6ddf-ba2a-40f3-8926-aa2d0d6b6603/77753442154.pdf
- https://uploads.strikinglycdn.com/files/ccba15d6-9c28-4c42-87ec-7b025349512d/nikupedex.pdf
- https://uploads.strikinglycdn.com/files/fdd327fc-7047-41e6-b8ea-dc7867a7e7f9/24823592147.pdf
- https://uploads.strikinglycdn.com/files/469690bc-158f-40bc-b3be-dc37a03e9a9c/17093278350.pdf
- https://uploads.strikinglycdn.com/files/adc570b0-74f9-47a9-8189-a749ee25a07c/jajulonifutobora.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7c9f57.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- lipowuripipu.weebly.com
- jikolugoxolij.weebly.com
- kelobutino.weebly.com
- netulomite.weebly.com
- genigudepa.weebly.com
- dutitujazekap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report