SUSPICIOUS — 0626a.pdf
SUSPICIOUS — 0626a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
77a4aa17ee168e060723044b3fec25279d6af8428652a822b165daadbc12b4fa - SHA-1:
cd39bf159912426ab427cef737639e5a8c197d07 - MD5:
3fc8b8ed4543add653414b480d827597 - ssdeep:
768:JgGzpDyuWz9IrlejswOo3y/Fiz9CffMFJosOFkvgfiXA4VGJLlBY89W0PL:qGFedze5e1Nz9CHpsOchXA4VMjYURL - TLSH:
T1DC329DF70193DE4C7AC79F07AEA62499A08AD3896136A76054CC773CC5BC5FDAE00960 - Submitted as: 0626a.pdf
- File type: pdf · Size: 46156 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=cub%20scout%20law%20game, https://uploads.strikinglycdn.com/files/3989464f-0ead-47ed-bbcf-2ff96514553a/hack_fastmail_account.pdf, https://uploads.strikinglycdn.com/files/0e9ca230-53b2-4b1f-bd2a-d12183f1b7bc/zedafokenovef.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=cub%20scout%20law%20game
- https://uploads.strikinglycdn.com/files/3989464f-0ead-47ed-bbcf-2ff96514553a/hack_fastmail_account.pdf
- https://uploads.strikinglycdn.com/files/0e9ca230-53b2-4b1f-bd2a-d12183f1b7bc/zedafokenovef.pdf
- https://s3.amazonaws.com/paxivogedewilu/tebuzola.pdf
- https://cdn-cms.f-static.net/uploads/4372735/normal_5f9747654791b.pdf
- https://s3.amazonaws.com/tetazino/tajuji.pdf
- https://uploads.strikinglycdn.com/files/e921a273-ca48-475b-9ed3-22f6d44fd61e/fodomexi.pdf
- https://uploads.strikinglycdn.com/files/7108afef-7b0e-46a4-ac5e-ca110d177488/gepadigapomozawug.pdf
- https://uploads.strikinglycdn.com/files/872821f8-6593-484e-b45e-c13d603bf45f/jakepix.pdf
- https://uploads.strikinglycdn.com/files/daf7867c-dd28-4b3d-ae74-ea26c80c676a/arithmetic_density_vs_physiological_density.pdf
- https://uploads.strikinglycdn.com/files/8f94ca12-71b8-4f7b-8a5b-f11b695fe21b/juzodiposawekib.pdf
- https://cdn-cms.f-static.net/uploads/4413705/normal_5f9c7dc738614.pdf
- https://cdn-cms.f-static.net/uploads/4381534/normal_5f9b951f379b4.pdf
- https://s3.amazonaws.com/pazifetanegapu/71531410981.pdf
- https://cdn-cms.f-static.net/uploads/4384164/normal_5f94938e60e69.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f93ed209350e.pdf
- https://s3.amazonaws.com/bubodeliza/holt_mcdougal_mathematics_grade_7_answers.pdf
- https://s3.amazonaws.com/jebupofedijakuk/fubegov.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report