SUSPICIOUS — 4fab3e13.pdf
SUSPICIOUS — 4fab3e13.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7f6fd14ba05ce356d61a903a5882969780f8b4215c72780ee1e241fa30d21472 - SHA-1:
21de4bcc8c2115d5f6a13995122394c318439a62 - MD5:
2049a0fd431947f47c416443f14db164 - ssdeep:
768:zQgGzpDkpfKjmy8gch1WJvmZmDf3s1sh94c7iBQb56nCAyX3TOx+W2VeiZYuadN:z9GF4pyvmZmDvish2c7h56nCtz4+W2Va - TLSH:
T178338EF350A7DC4C7A8BDB437DFA20586549D7882033ABA084C96B6CC4B87BD7E50911 - Submitted as: 4fab3e13.pdf
- File type: pdf · Size: 48387 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=2020%20calendar%20with%20holidays%20template, https://cdn-cms.f-static.net/uploads/4366982/normal_5f874528e21da.pdf, https://cdn-cms.f-static.net/uploads/4366304/normal_5f8730fc8c5ea.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=2020%20calendar%20with%20holidays%20template
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f874528e21da.pdf
- https://cdn-cms.f-static.net/uploads/4366304/normal_5f8730fc8c5ea.pdf
- https://cdn-cms.f-static.net/uploads/4365624/normal_5f870a416db34.pdf
- https://uploads.strikinglycdn.com/files/431c2a26-6318-43ac-b66e-12881408a0f3/5187093999.pdf
- https://uploads.strikinglycdn.com/files/dc9830c8-10df-4f42-910f-34a6a6ef1d87/xebetibapulumolidu.pdf
- https://uploads.strikinglycdn.com/files/c651269a-4dc7-4845-8e57-34276e311872/lukelafezizekikewogonodiv.pdf
- https://cdn-cms.f-static.net/uploads/4365608/normal_5f87245fa28ec.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f87026dba6c6.pdf
- https://site-1038955.mozfiles.com/files/1038955/20077891504.pdf
- https://site-1042349.mozfiles.com/files/1042349/87551652740.pdf
- https://site-1039693.mozfiles.com/files/1039693/transmission_line_design.pdf
- https://site-1042346.mozfiles.com/files/1042346/23874688707.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f870b6f504c2.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87452155321.pdf
- https://uploads.strikinglycdn.com/files/4e320f44-e942-4714-8e09-3bcb6161cb24/dokomoni.pdf
- https://uploads.strikinglycdn.com/files/071c3bed-394c-4772-b3d5-a33f981eea57/xusogixarowuwubaxafetelu.pdf
- https://uploads.strikinglycdn.com/files/fbfb0c23-08f7-4641-8dfc-903a3a79e6fa/12343620584.pdf
- https://uploads.strikinglycdn.com/files/5022cdea-416d-41a2-87e8-50f296236c77/wemujowebifex.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038955.mozfiles.com
- site-1042349.mozfiles.com
- site-1039693.mozfiles.com
- site-1042346.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report