SUSPICIOUS — 6005180.pdf
SUSPICIOUS — 6005180.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
560fbf04325fa9fb26c5852091db7ec98bf1da571a7c98717087c4887a94b82d - SHA-1:
6f13aaa4336d9a5be5b12e65371135242aebfd26 - MD5:
bc1ddfc725e19f3d30743a348ef5c536 - ssdeep:
768:sgGzpDKpggt6MAxwUX8Y0NJ81REudHSkcbb1kcYBfCS/b7nLD:pGFupj0Ab8fEW+b+c0n/b7LD - TLSH:
T1B6329EF354ABEE4C7A879B07ADA60564258ED78C7232979044CC372D94BCAFD7E10920 - Submitted as: 6005180.pdf
- File type: pdf · Size: 43634 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=casa%20essentials%20pressure%20cooker%205%20qt%20manual, https://site-1039257.mozfiles.com/files/1039257/xesomimurorizekuxixinef.pdf, https://site-1038946.mozfiles.com/files/1038946/71088431876.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=casa%20essentials%20pressure%20cooker%205%20qt%20manual
- https://site-1039257.mozfiles.com/files/1039257/xesomimurorizekuxixinef.pdf
- https://site-1038946.mozfiles.com/files/1038946/71088431876.pdf
- https://site-1043357.mozfiles.com/files/1043357/gazawigufirugota.pdf
- https://site-1043694.mozfiles.com/files/1043694/nobufaro.pdf
- https://site-1037160.mozfiles.com/files/1037160/zosolamepisetavoxator.pdf
- https://cdn-cms.f-static.net/uploads/4368752/normal_5f87a9d61beba.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f8750164e8d0.pdf
- https://cdn-cms.f-static.net/uploads/4366676/normal_5f87470c31e6e.pdf
- https://cdn-cms.f-static.net/uploads/4368999/normal_5f87dc3dee548.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f876cef57dfe.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f87622d7ee50.pdf
- https://cdn-cms.f-static.net/uploads/4369511/normal_5f87c6d7077d5.pdf
- https://berajuvexoru.weebly.com/uploads/1/3/1/8/131860787/fuvoz.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/xopevu_vilugarokobijos_fimorekon.pdf
- https://melegejisud.weebly.com/uploads/1/3/1/3/131379421/9211530.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/6448319.pdf
- https://uploads.strikinglycdn.com/files/67cb26e4-f78c-491e-83d0-e3b25c89b909/42232848042.pdf
- https://uploads.strikinglycdn.com/files/d75464b2-65f1-4f3e-b8be-bdd9b17733d9/45619804912.pdf
- https://uploads.strikinglycdn.com/files/ef0cf1d6-814d-4a3e-a796-a6cefe4ae2ec/75279213333.pdf
- https://uploads.strikinglycdn.com/files/90e4d8d8-207e-42a5-ab2c-b871b803a140/3259401157.pdf
- https://uploads.strikinglycdn.com/files/16ab5a57-35dd-493d-ad78-79757f8b613b/wisazaros.pdf
- https://uploads.strikinglycdn.com/files/8bb9c2a7-08b7-4de2-96dc-42f5fd0489f8/17298967978.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- site-1039257.mozfiles.com
- site-1038946.mozfiles.com
- site-1043357.mozfiles.com
- site-1043694.mozfiles.com
- site-1037160.mozfiles.com
- cdn-cms.f-static.net
- berajuvexoru.weebly.com
- jawasolasazilem.weebly.com
- melegejisud.weebly.com
- pumowurunumig.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report