SUSPICIOUS — 465fa1cb6d8cd43.pdf
SUSPICIOUS — 465fa1cb6d8cd43.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7af65faa0506d729d70d755eb0aabc3d4058b673bb4e8e3cbffae74e455b41c3 - SHA-1:
e85f1ed1273e909624e21caf7dfc2077a6de29b3 - MD5:
5f12af1cf8f925e111d66603a8e21554 - ssdeep:
768:HgGzpDPp/e/Ib5tQLD/eCJUtKwB3/f3m0JR9+/PGVGyDxk1jWNE:AGF7p/doNFY3H3tZ+/PLwS1jWNE - TLSH:
T1CF317CF34497ED8C7A86AB43AEBB01562149C74D6136E7A045CC372CD4BC6BD7E208A1 - Submitted as: 465fa1cb6d8cd43.pdf
- File type: pdf · Size: 42684 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=unshakeable%20pdf%20free%20download, https://uploads.strikinglycdn.com/files/f444cae9-d2a6-4d3e-b3e8-b22403e18684/16940457987.pdf, https://uploads.strikinglycdn.com/files/959171fe-201f-4844-8179-562c97a0d108/31468260386.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=unshakeable%20pdf%20free%20download
- https://uploads.strikinglycdn.com/files/f444cae9-d2a6-4d3e-b3e8-b22403e18684/16940457987.pdf
- https://uploads.strikinglycdn.com/files/959171fe-201f-4844-8179-562c97a0d108/31468260386.pdf
- https://uploads.strikinglycdn.com/files/0cfff884-9d8e-4ce1-8e02-cf1bfab2e265/17460043429.pdf
- https://cdn.shopify.com/s/files/1/0499/4246/2618/files/71831327200.pdf
- https://cdn.shopify.com/s/files/1/0501/5512/6949/files/zirododa.pdf
- https://cdn.shopify.com/s/files/1/0485/0778/1281/files/vikixinuvixeb.pdf
- https://cdn.shopify.com/s/files/1/0484/6996/7013/files/breast_screening_guidelines_us.pdf
- https://cdn.shopify.com/s/files/1/0266/8114/7582/files/71854395084.pdf
- https://xalipifizipig.weebly.com/uploads/1/3/1/3/131379045/wokadoxejobonug.pdf
- https://giwakatunu.weebly.com/uploads/1/3/1/4/131437107/dixatenebiw_lunagor_datuwa.pdf
- https://s3.amazonaws.com/salade/que_es_employer_branding.pdf
- https://s3.amazonaws.com/felasorarabipis/dajiwavemadawoto.pdf
- https://uploads.strikinglycdn.com/files/4303c05c-95af-4ac0-bde9-c12f6ef73751/41856402749.pdf
- https://uploads.strikinglycdn.com/files/18eaa068-18c1-408f-a8d5-411e48b1077e/tufegopugeteza.pdf
- https://uploads.strikinglycdn.com/files/5818ab18-de4e-4db4-b9d7-4994f84737fb/computer_repair_guide_book.pdf
- https://uploads.strikinglycdn.com/files/9ab8acd5-1d03-4432-8594-7a676664d1a1/wuwomozinagilimunibilowa.pdf
- https://uploads.strikinglycdn.com/files/2a779a3d-a40c-4b48-b393-bb74ba65e030/piano_notes_chart_88_keys.pdf
- https://uploads.strikinglycdn.com/files/e0be285e-4eec-43cd-89af-567edbc00498/pevumaxeteduwokavebawiv.pdf
- https://uploads.strikinglycdn.com/files/4ddd3575-ab55-4013-ab24-89e398377266/kanuxilov.pdf
- https://uploads.strikinglycdn.com/files/db4f9caf-06b4-415e-bba9-a7da4d633b21/diluduxepanun.pdf
- https://uploads.strikinglycdn.com/files/1d942300-0fb8-4587-8839-988bf78b1078/wijusijoderaja.pdf
- https://www.cancer.gov/coronavirus
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- xalipifizipig.weebly.com
- giwakatunu.weebly.com
- s3.amazonaws.com
- www.cancer.gov
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report