SUSPICIOUS — 0cab35da0b1.pdf
SUSPICIOUS — 0cab35da0b1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7a6b08742ded47dbcb2823587ac2e2e624ef333b262203a09f9dd770ca740b94 - SHA-1:
24f5ad5e20e620e593617b223efc0fc5888fba86 - MD5:
eaa6862b5097222f90534c0ac42d504f - ssdeep:
768:SgGzpDfpcah7B79IuD2ISIVkv526i8aFnXTWttsY0DObeC:PGFrprI2dSIVY2l02VObeC - TLSH:
T1BE329EF344ABED8C79CABB039EE70555218DC38C613297205488772DD4BC6BDBE14AA1 - Submitted as: 0cab35da0b1.pdf
- File type: pdf · Size: 43389 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=individual%20provider%20washington%20state, https://uploads.strikinglycdn.com/files/cb5c12a2-1f2c-4afd-8a12-b20e6486530d/45690616695.pdf, https://uploads.strikinglycdn.com/files/7bdd1c75-640a-42a9-be56-1cdc17e18818/27317319804.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=individual%20provider%20washington%20state
- https://uploads.strikinglycdn.com/files/cb5c12a2-1f2c-4afd-8a12-b20e6486530d/45690616695.pdf
- https://uploads.strikinglycdn.com/files/7bdd1c75-640a-42a9-be56-1cdc17e18818/27317319804.pdf
- https://uploads.strikinglycdn.com/files/4fd32e47-1144-47ff-8b1d-b7f9202fad35/vuloramifuvo.pdf
- https://uploads.strikinglycdn.com/files/dc5ae160-fb5f-4005-adb3-f8f0f4c70b6f/77251331943.pdf
- https://junoxavod.weebly.com/uploads/1/3/1/3/131384771/a9e66ad38a58f86.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/didof_bogula_turixewukak.pdf
- https://xanodupujariris.weebly.com/uploads/1/3/0/9/130969381/buzidu.pdf
- https://xisubuto.weebly.com/uploads/1/3/1/3/131380177/viselobapixirudu.pdf
- https://sixapinipuso.weebly.com/uploads/1/3/1/3/131384402/161732.pdf
- https://uploads.strikinglycdn.com/files/89fb1104-df79-4a77-b7fa-365736d1289e/90042260382.pdf
- https://uploads.strikinglycdn.com/files/e4ce0dea-1cf0-4762-bf7f-9b5f90b64cad/65194445337.pdf
- https://uploads.strikinglycdn.com/files/0f9bc977-1ddd-43bc-9ca8-31db21a37659/70747296599.pdf
- https://uploads.strikinglycdn.com/files/ebfba986-997e-4b4a-a201-0584a7c17b44/blockly_games_movie_answers.pdf
- https://uploads.strikinglycdn.com/files/a9aefb26-38d7-4189-a973-12e80cd32d2d/sorim.pdf
- https://uploads.strikinglycdn.com/files/8141e20b-9043-4d24-9c60-30e818f61275/rewiz.pdf
- https://uploads.strikinglycdn.com/files/f3322a47-e541-49f6-bf60-4cfa4d508f6f/33512164844.pdf
- https://uploads.strikinglycdn.com/files/0380d3ac-e67c-4dc2-9e64-4201b902fb5f/86248657258.pdf
- https://uploads.strikinglycdn.com/files/a838beab-6055-49ea-83af-9b4552808b9d/92689583524.pdf
- https://uploads.strikinglycdn.com/files/ff9b87e4-fc6c-47bf-a649-bcd6429c0e90/welumugaxovukibi.pdf
- https://uploads.strikinglycdn.com/files/81db7bce-1a1b-4544-bbca-962b746fbe03/35436608100.pdf
- https://uploads.strikinglycdn.com/files/8fd238bf-fbdf-4e91-a7f5-49b504adeb55/cahier_de_vacances_pour_adultes_gratuit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- junoxavod.weebly.com
- zimiduninu.weebly.com
- xanodupujariris.weebly.com
- xisubuto.weebly.com
- sixapinipuso.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report