SUSPICIOUS — fcc2e37718f2b4d.pdf
SUSPICIOUS — fcc2e37718f2b4d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
56a36bc07db5848221b9fb6b838f1a92e1bd62a3d8059788de33b4e58afaa4c5 - SHA-1:
ec8c98561176b89eaab137c82d1fd32973685c6e - MD5:
5f3d73db0b7f898e231c709ef3dc84ae - ssdeep:
768:qgGzpDcQYQt3tlaD/ruVktNhq9KN267Gpfl5nGzjYrGnzruo1:3GFQQGDM+hq9A26CpvnGzjYrGzruo1 - TLSH:
T19F339EF340A7DC8C7A8BAB47AAAB2558614AC7483035A79044CC772CC8BC2FD7D65961 - Submitted as: fcc2e37718f2b4d.pdf
- File type: pdf · Size: 49021 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hp%20printer%20envy%205660%20user%20manual, https://uploads.strikinglycdn.com/files/ac99f166-9152-406f-93f6-bd63d9cd4986/dadomewofafelurokolajeba.pdf, https://uploads.strikinglycdn.com/files/84a0eda3-107e-4d00-b02c-00c175625a68/eleven_and_max_ship.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hp%20printer%20envy%205660%20user%20manual
- https://uploads.strikinglycdn.com/files/ac99f166-9152-406f-93f6-bd63d9cd4986/dadomewofafelurokolajeba.pdf
- https://uploads.strikinglycdn.com/files/84a0eda3-107e-4d00-b02c-00c175625a68/eleven_and_max_ship.pdf
- https://uploads.strikinglycdn.com/files/27e24fec-8b64-4361-86ca-fb9d30459927/59568826815.pdf
- https://uploads.strikinglycdn.com/files/dbd0cfd0-ced6-4f32-b7ff-bf62fe0aa837/26341907046.pdf
- https://s3.amazonaws.com/wenobagupexekap/zufekatexobosoxewusi.pdf
- https://uploads.strikinglycdn.com/files/414b0200-9cc3-4a87-adf4-4e9bd87eb941/frozen_the_movie_for_free.pdf
- https://uploads.strikinglycdn.com/files/291c5641-834f-4beb-8f6a-283c9fb3429b/assistir_filmes_8_segundos_dublado_o.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/supazebiguzor.pdf
- https://uploads.strikinglycdn.com/files/fde36e11-13bf-41be-b9e6-a407e63513dd/43903324718.pdf
- https://vogoworelo.weebly.com/uploads/1/3/4/2/134266182/sunaxenipabonig.pdf
- https://s3.amazonaws.com/bidivo/aristotle_the_rhetoric.pdf
- https://uploads.strikinglycdn.com/files/c46cc288-c22c-4f9f-9313-b82cb42d8296/barolo_vintage_chart.pdf
- https://uploads.strikinglycdn.com/files/47006a85-3a20-4338-aa04-2380ec6b11a8/29104609443.pdf
- https://s3.amazonaws.com/tixedujegibex/game_theory_examples.pdf
- https://s3.amazonaws.com/lewuli/hospital_accountant_job_description.pdf
- https://uploads.strikinglycdn.com/files/91e0418a-8f4c-4918-9109-2cae1dfe12f5/7203652900.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- xojisige.weebly.com
- vogoworelo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report