SUSPICIOUS — 67596aeca06.pdf
SUSPICIOUS — 67596aeca06.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
6dcfe062f1cc0be5204f676fb337f7d918cab5389a62471e0a56a1996f2e6c40 - SHA-1:
d45b0137fdcfc1a7bc101a07d7d35a7e661c8ba2 - MD5:
557ee34ce1f36a794d308cea1fd526a2 - ssdeep:
768:3gGzpD77vaP9fZBhvD70lhnaB807phsnzzMb66AD89:QGFnzMphNAD89 - TLSH:
T1922F6BF700A7ED4C7B8B9F83ADA71199918AD28C2136E360059C766CD4BC6BD7F00951 - Submitted as: 67596aeca06.pdf
- File type: pdf · Size: 35663 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=yds%20deneme%20s%C4%B1nav%C4%B1%20pdf, https://cdn.shopify.com/s/files/1/0500/5318/5685/files/bypass_lock_screen_android_apk.pdf, https://cdn.shopify.com/s/files/1/0498/3357/4555/files/zadixutesi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=yds%20deneme%20s%C4%B1nav%C4%B1%20pdf
- https://cdn.shopify.com/s/files/1/0500/5318/5685/files/bypass_lock_screen_android_apk.pdf
- https://cdn.shopify.com/s/files/1/0498/3357/4555/files/zadixutesi.pdf
- https://cdn.shopify.com/s/files/1/0495/6310/7480/files/kexuk.pdf
- https://cdn.shopify.com/s/files/1/0497/7888/4759/files/download_line_launcher_latest_version_apk.pdf
- https://cdn.shopify.com/s/files/1/0428/5281/0911/files/48790075569.pdf
- https://cdn.shopify.com/s/files/1/0496/1438/9412/files/fairfield_magnet_school_winnsboro_sc_29180.pdf
- https://cdn.shopify.com/s/files/1/0496/9214/7869/files/67367699551.pdf
- https://buliduxefexefux.weebly.com/uploads/1/3/1/6/131636978/0562a1cc14d5d7.pdf
- https://xonimitofowe.weebly.com/uploads/1/3/2/6/132682232/jegigexekadejew-revifimidixewo-faxasugo-botenefikajid.pdf
- https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/vejuli.pdf
- https://cdn.shopify.com/s/files/1/0268/7513/4135/files/manuali_scrittura_creativa.pdf
- https://cdn.shopify.com/s/files/1/0438/6629/2389/files/selective_attention_psychology_definition_example.pdf
- https://cdn.shopify.com/s/files/1/0440/0267/2798/files/best_card_shuffler.pdf
- https://s3.amazonaws.com/jeromopelurab/84612969106.pdf
- https://s3.amazonaws.com/mijedusovineti/rocket_propulsion_elements_ninth_edition.pdf
- https://uploads.strikinglycdn.com/files/b12408b5-b5db-41ce-a9fe-927b7239e896/lazujagegutuvol.pdf
- https://uploads.strikinglycdn.com/files/aa5aa25a-be64-4f95-b53f-f296f40213be/97462201654.pdf
- https://uploads.strikinglycdn.com/files/a3ba2e9e-495a-4504-878b-77e3916263f8/67600507905.pdf
- https://uploads.strikinglycdn.com/files/b20e6abb-d807-4391-be51-d7261305f71c/56140633438.pdf
- https://uploads.strikinglycdn.com/files/3ea4eaaf-88d1-420c-bc9c-b7387946d77e/kogoxufijumefaj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- buliduxefexefux.weebly.com
- xonimitofowe.weebly.com
- sanuvexugivi.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report