SUSPICIOUS — 0f491d10a60.pdf
SUSPICIOUS — 0f491d10a60.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
926174d5e870b5b59a807704f940fef81ca5c2f487dee4267cea561b8692df03 - SHA-1:
9cc19922384729509009c1b05b0d60d08a5df0a2 - MD5:
de9cb8c65d1d3fdb749bcd4f783e3cae - ssdeep:
768:xgGzpDzg7QrPApPS4w8G/38M82ub6C8IUmwde3ICBaf1BYqm:CGFXksh82e6uws3FqBYqm - TLSH:
T164306CF34093ED4D3E869F036EAA251D558EC3896036E260059C3B6CE5BC6BE3F50961 - Submitted as: 0f491d10a60.pdf
- File type: pdf · Size: 37567 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=faac%20wireless%20safety%20edge%20manual, https://cdn.shopify.com/s/files/1/0480/9464/2340/files/jopamavonolexinerujunu.pdf, https://cdn.shopify.com/s/files/1/0484/5597/5062/files/39458061376.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=faac%20wireless%20safety%20edge%20manual
- https://cdn.shopify.com/s/files/1/0480/9464/2340/files/jopamavonolexinerujunu.pdf
- https://cdn.shopify.com/s/files/1/0484/5597/5062/files/39458061376.pdf
- https://s3.amazonaws.com/gupuso/81057060394.pdf
- https://cdn.shopify.com/s/files/1/0492/7481/4620/files/where_is_edmonton_county.pdf
- https://cdn.shopify.com/s/files/1/0484/3841/1422/files/jibiri.pdf
- https://uploads.strikinglycdn.com/files/d7d37ec7-29af-492a-b49a-054a870b8421/ap_biology_book_9th_edition_online.pdf
- https://s3.amazonaws.com/salosibejodod/xezene.pdf
- https://cdn.shopify.com/s/files/1/0268/7723/1275/files/zerotuwapijobumopidafunag.pdf
- https://cdn.shopify.com/s/files/1/0266/8235/9987/files/definicion_de_cohesion_grupal.pdf
- https://uploads.strikinglycdn.com/files/1ebb0e14-63b4-4755-962e-6409fd513263/zubixegekej.pdf
- https://cdn.shopify.com/s/files/1/0482/7014/7739/files/12623588002.pdf
- https://uploads.strikinglycdn.com/files/9b36b62d-11ec-4892-985e-97ecd16b95e4/pujutenabivetowaju.pdf
- https://uploads.strikinglycdn.com/files/d2168dc3-be94-48fe-8ccf-51129e5df934/1144383828.pdf
- https://cdn.shopify.com/s/files/1/0483/4079/5555/files/fokididilinunizulatujoj.pdf
- https://uploads.strikinglycdn.com/files/2b603d67-d64a-4b4c-b08a-6e9820d70fe0/westlife_album_download_blogspot.pdf
- https://uploads.strikinglycdn.com/files/4f46f888-1293-434f-9798-214b4d459bb4/31357822667.pdf
- https://s3.amazonaws.com/susopuzupure/78703502394.pdf
- https://uploads.strikinglycdn.com/files/b38caf54-360b-4139-a0cb-0485a91a2fb2/too_much_sugar_in_coffee_meme.pdf
- https://cdn.shopify.com/s/files/1/0493/3838/4543/files/manual_ip_address_raspberry_pi.pdf
- https://uploads.strikinglycdn.com/files/23857abe-47d6-40af-afe8-773dbfb7f45d/peluxoranegolojixolus.pdf
- https://uploads.strikinglycdn.com/files/353117bd-b744-42e7-ab79-3004b731940c/53801093013.pdf
- https://uploads.strikinglycdn.com/files/4ff4ec3a-3e26-4fea-92c7-89ff439cafdb/sibusuzobugivofijiwip.pdf
- https://cdn.shopify.com/s/files/1/0501/9936/3764/files/drawboard_surface_book.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report