SUSPICIOUS — 63715ac052299.pdf
SUSPICIOUS — 63715ac052299.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
71e464573816c6921972e9f9e3195794375255366df03c0ea6bde3fbea6dd78d - SHA-1:
f2cb0041d376e6f715991be8803c2423f7038dc7 - MD5:
f78ab6c3164cd532cc4bc424b17187bf - ssdeep:
768:ygGzpDEwT/3nJ3MjsFYK6jmUXVYhKcxS6wn15td2z9uBFOZSZLAdKs3:vGFgwT/tjFh0YhK115tYMBIZSZLAdKs3 - TLSH:
T133319EF3919BED8C6A86DF03ACEA15196049D68E722157B044D87B7CC4BC2BE6E40C61 - Submitted as: 63715ac052299.pdf
- File type: pdf · Size: 41875 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffine.ru/wb?keyword=how%20to%20scam%20on%20animal%20jam%20play%20wild, https://cdn-cms.f-static.net/uploads/4391326/normal_5f9dcd7c714b9.pdf, https://cdn-cms.f-static.net/uploads/4423780/normal_5fa4ff55b7cd8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffine.ru/wb?keyword=how%20to%20scam%20on%20animal%20jam%20play%20wild
- https://cdn-cms.f-static.net/uploads/4391326/normal_5f9dcd7c714b9.pdf
- https://wirovoxujeme.files.wordpress.com/2020/11/99349908726.pdf
- https://cdn-cms.f-static.net/uploads/4423780/normal_5fa4ff55b7cd8.pdf
- https://s3.amazonaws.com/wutezigojuxi/58464031695.pdf
- https://s3.amazonaws.com/defipedibe/ziliruj.pdf
- https://s3.amazonaws.com/sinamozagemoger/pemomib.pdf
- https://s3.amazonaws.com/dapekufoxiraku/trout_stocking_schedule_oregon.pdf
- https://lavukiju.files.wordpress.com/2020/11/kesozexinajemikidip.pdf
- https://gidixuvunibu.files.wordpress.com/2020/11/avengers_infinity_war_stream_online_free.pdf
- https://s3.amazonaws.com/tibitexil/zepimojebuzasen.pdf
- https://pavezisetapo.files.wordpress.com/2020/11/fundamentals_of_structural_analysis.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffine.ru
- cdn-cms.f-static.net
- wirovoxujeme.files.wordpress.com
- s3.amazonaws.com
- lavukiju.files.wordpress.com
- gidixuvunibu.files.wordpress.com
- pavezisetapo.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report