SUSPICIOUS — e04622d.pdf
SUSPICIOUS — e04622d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
5b558c072334931e949cdf244bb1b5ee0e6443a91c2c281968375488720bb5ed - SHA-1:
d3aa40a57424627992ea6fb9adc56c91eaf25d6f - MD5:
67360e38201c1d6cdf2f84f182a2c73e - ssdeep:
768:zgGzpDrwJ22ui1+enZDo1zttYJk3ue32cIx8ShTcy0vHf66c8mji:MGFvwJ2am0EvIx8KTF6c8mji - TLSH:
T1F6307EF31097ED8C7B8A9B479DE711A5548EDB8D60378BA0148C672CC4BCAED3E10A11 - Submitted as: e04622d.pdf
- File type: pdf · Size: 37122 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=renewable%20energy%20sources%20and%20conversion%20technology%20pdf, https://cdn-cms.f-static.net/uploads/4366625/normal_5f8750af76980.pdf, https://cdn-cms.f-static.net/uploads/4365660/normal_5f87671852cc8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=renewable%20energy%20sources%20and%20conversion%20technology%20pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f8750af76980.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f87671852cc8.pdf
- https://cdn-cms.f-static.net/uploads/4380863/normal_5f8c35853b092.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f9305d534c98.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f86f8450d45a.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f936e0a775e9.pdf
- https://uploads.strikinglycdn.com/files/782d986a-9a5f-4235-9061-2beaf5d1b422/30866597404.pdf
- https://uploads.strikinglycdn.com/files/8ff19827-20f7-447a-ade7-aae519a1e3ca/sefoxadevuwijasedenotanem.pdf
- https://uploads.strikinglycdn.com/files/17859626-aa1d-46cc-8dc7-6f70c01cb259/mivesifunamudosedem.pdf
- https://uploads.strikinglycdn.com/files/f93b1383-b7ef-4b16-8c0b-0cbafdf68844/pudixezasidetofulorowep.pdf
- https://uploads.strikinglycdn.com/files/ebc87a5e-9f71-46b5-ade0-1ffe85b4f95b/8303574404.pdf
- https://siregudak.weebly.com/uploads/1/3/0/7/130738759/8cd8c8.pdf
- https://xesaranit.weebly.com/uploads/1/3/2/6/132696194/vakiwusi_zerarupuzapesu_zuxorivikabedok.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/segifelesilokunuva.pdf
- https://suganolorifumu.weebly.com/uploads/1/3/0/8/130814011/bajew.pdf
- https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/rilofovu.pdf
- https://pepisukuwen.weebly.com/uploads/1/3/1/6/131606293/natupojikumeb-xovovetogowup-susifinit.pdf
- https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/danuve.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/ruselawefujolad.pdf
- https://xukaxikerebata.weebly.com/uploads/1/3/4/0/134042698/folojosiki-pejejil-bomap-moketajoribekab.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/lipefamowaf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- siregudak.weebly.com
- xesaranit.weebly.com
- walijogopabo.weebly.com
- suganolorifumu.weebly.com
- seririgikum.weebly.com
- pepisukuwen.weebly.com
- nipufijupetobug.weebly.com
- besiwalufeg.weebly.com
- xukaxikerebata.weebly.com
- ditiwudo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report