SUSPICIOUS — ee27b50c64faae.pdf
SUSPICIOUS — ee27b50c64faae.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7b4b102c95fa17c4bd124a771d32233633e90ae01c4ac0f8da70d4d5108d91db - SHA-1:
4c273b642418b1986b9a4ee22eb4d093b6160cbf - MD5:
a8da3037b240d5d910c0fe5e1a47d560 - ssdeep:
1536:6GFheW0W+ZNiE0y5V0H6RkX7SmHG0cXQ:jFheFW+ZDv2X7fHG0D - TLSH:
T1EF34AFF700E7EC4C3A8B9B43AEAA1059A54AD78DA1369B5054C97B2CC47C2FC7E10E51 - Submitted as: ee27b50c64faae.pdf
- File type: pdf · Size: 57536 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=free%20access%20tutorial, https://cdn-cms.f-static.net/uploads/4368466/normal_5f89085794fe7.pdf, https://cdn-cms.f-static.net/uploads/4366389/normal_5f87142509b40.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=free%20access%20tutorial
- https://cdn-cms.f-static.net/uploads/4368466/normal_5f89085794fe7.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f87142509b40.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f875d71be384.pdf
- https://cdn-cms.f-static.net/uploads/4375894/normal_5f8b2c8f8cb91.pdf
- https://uploads.strikinglycdn.com/files/5d9e1492-5d7d-4eab-be04-c55ae49c1ba8/99549967465.pdf
- https://uploads.strikinglycdn.com/files/5f7a2035-5e9c-4531-9fa7-f2d3b8b7f73b/65542411644.pdf
- https://uploads.strikinglycdn.com/files/c5e669b9-d421-4046-b10d-b5363587a83b/37679726023.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/04609804.pdf
- https://duxixujojive.weebly.com/uploads/1/3/0/7/130739103/mukej-jepefalolamux-vuxevine.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tugunari_fogeze_nezejavoz.pdf
- https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/vetuwexirara.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/4503832.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/xexojosaxexuwa.pdf
- https://wirukibit.weebly.com/uploads/1/3/0/9/130969322/6738325.pdf
- https://jamafijuzu.weebly.com/uploads/1/3/1/4/131437216/8313658.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/8358579.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/862f27556c.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/e1d84cd9c07f.pdf
- https://wopuremob.weebly.com/uploads/1/3/2/6/132696580/sufuzagipiv-divoxizidegewor-famevitesi-waxaraxiza.pdf
- https://gituwere.weebly.com/uploads/1/3/0/7/130740556/1562145.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- megadezatesaram.weebly.com
- duxixujojive.weebly.com
- guwomenod.weebly.com
- zuwumepegowivos.weebly.com
- vozunutav.weebly.com
- sesuwulot.weebly.com
- wirukibit.weebly.com
- jamafijuzu.weebly.com
- lodirunesu.weebly.com
- pevugubak.weebly.com
- dutitujazekap.weebly.com
- wopuremob.weebly.com
- gituwere.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report