SUSPICIOUS — fbcb5a0c9ef863.pdf
SUSPICIOUS — fbcb5a0c9ef863.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
65d86c27eba3062be71dc736885ba93e0e03f096711d69d7aeb38a57fbcc4498 - SHA-1:
b613a531d46c3ea1b2345d273f2dd281bb10693b - MD5:
201295154a603d49f1002f0473f13196 - ssdeep:
768:ngGzpD6wj/LXKHaz1HxufGYg803yF85Rj+XRooRaGpwK2Ht/sd41GWSjAv4YCtZK:gGFeejKw3LiTlpf2RGWGWSvftZTH4N - TLSH:
T12335BFF71197EC8C7A8AAF0369B62458218AC74CB5369A6445DC7F7D803C3BC7E019A1 - Submitted as: fbcb5a0c9ef863.pdf
- File type: pdf · Size: 61287 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=gtunes%20music%20app, https://uploads.strikinglycdn.com/files/71ab5efe-23bb-479e-b136-e9d8a8a84153/83102738929.pdf, https://uploads.strikinglycdn.com/files/ea82d94a-f1d0-4ffd-9336-ce1dffccd2ba/30966644953.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=gtunes%20music%20app
- https://uploads.strikinglycdn.com/files/71ab5efe-23bb-479e-b136-e9d8a8a84153/83102738929.pdf
- https://s3.amazonaws.com/posufij/explanation_of_allah_s_names.pdf
- https://s3.amazonaws.com/wovigebi/75365322115.pdf
- https://s3.amazonaws.com/zosevid/wafobelobarozerujosivu.pdf
- https://uploads.strikinglycdn.com/files/ea82d94a-f1d0-4ffd-9336-ce1dffccd2ba/30966644953.pdf
- https://s3.amazonaws.com/gupuso/556375356.pdf
- https://s3.amazonaws.com/susopuzupure/37063864012.pdf
- https://uploads.strikinglycdn.com/files/2c245cba-6a9c-4e43-a706-096cb7e3d433/last_king_shirt_mens.pdf
- https://uploads.strikinglycdn.com/files/f6f0ea1e-5658-4a39-ba0f-7e95dc793065/what_is_form_it-201.pdf
- https://uploads.strikinglycdn.com/files/8f66f992-a048-406d-bb06-a5d9f136f217/putipusesolemifizafuxuxal.pdf
- https://uploads.strikinglycdn.com/files/802516cb-f70e-41ac-84d0-9750eb820c0e/dowazodojidufezavo.pdf
- https://s3.amazonaws.com/tejuvonixag/banijeduvilama.pdf
- https://s3.amazonaws.com/foneniz/tafsir_al_quran_dan_terjemahan.pdf
- https://s3.amazonaws.com/fizup/86197978315.pdf
- https://s3.amazonaws.com/bisute/byu_bball_schedule.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report