SUSPICIOUS — 65f78c9b.pdf
SUSPICIOUS — 65f78c9b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
940213abc0fee892bb0486d6861da6127b80d1d6f995c2c3bd542ac00a667043 - SHA-1:
9090bfed0df4544576dc6407c2e6a192bb82d4bf - MD5:
70b570af2f2f6f8f4ec2ce9cbaafa5a9 - ssdeep:
768:ZgGzpD+pElWEAaZn3Nlupb2uzWWGaJF4Jn1WQOT:aGFCpScpb26WIUn1WQOT - TLSH:
T18A2F6CF71097FCCC7E8FAB079DAB1199514AC78D603697A0098C772CD0BC6AD6E01A51 - Submitted as: 65f78c9b.pdf
- File type: pdf · Size: 34919 bytes
- Verdict: suspicious (35/100)
Detections (1 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=maths%20teacher%20resume%20format%20pdf, https://uploads.strikinglycdn.com/files/1486d014-9f7d-4c5e-a082-49945695af5a/25131366058.pdf, https://uploads.strikinglycdn.com/files/065e7bd4-fdcf-4deb-b8a3-38047fb0419d/graphing_absolute_value_inequalities_worksheet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=maths%20teacher%20resume%20format%20pdf
- https://uploads.strikinglycdn.com/files/1486d014-9f7d-4c5e-a082-49945695af5a/25131366058.pdf
- https://uploads.strikinglycdn.com/files/065e7bd4-fdcf-4deb-b8a3-38047fb0419d/graphing_absolute_value_inequalities_worksheet.pdf
- https://uploads.strikinglycdn.com/files/c6931cab-6e14-4966-b5da-d5a276484109/34706876085.pdf
- https://uploads.strikinglycdn.com/files/3f2a3bd4-e467-42f4-bb69-1f1a6c3a3318/mobilya_izim_program_indir.pdf
- https://cdn.shopify.com/s/files/1/0497/2891/3560/files/nomiwimugojaxefalibix.pdf
- https://cdn.shopify.com/s/files/1/0435/2891/3055/files/fadekekujedegeberupojuli.pdf
- https://uploads.strikinglycdn.com/files/4645ce2a-abbb-4f52-a942-2b5c48f60081/sezafuxopesiwunavi.pdf
- https://uploads.strikinglycdn.com/files/88af3f34-13c2-4777-8a36-59e293d7175a/65274534853.pdf
- https://uploads.strikinglycdn.com/files/515d0ea8-4572-4022-90de-d41c9e9b2d98/lamaz.pdf
- https://uploads.strikinglycdn.com/files/e6b46fd3-d23d-44e7-877d-50355a9e7ee2/click_clack_the_rattlebag_worksheet.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/gepim.pdf
- https://kikuvabafot.weebly.com/uploads/1/3/4/3/134332304/jinemafusagavuf-nivugutob.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/bagatazojiz_sidatasofugugor_sofaxazute_gureluf.pdf
- https://vibebivenef.weebly.com/uploads/1/3/1/4/131412032/bulivovajuzonabazide.pdf
- https://xesaranit.weebly.com/uploads/1/3/2/6/132696194/kajoj.pdf
- https://buveziketi.weebly.com/uploads/1/3/1/3/131398526/vupuxa.pdf
- https://degujipimisa.weebly.com/uploads/1/3/1/4/131453395/zexenifeni.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/3990354.pdf
- https://cdn-cms.f-static.net/uploads/4384470/normal_5f91f59502a1d.pdf
- https://cdn-cms.f-static.net/uploads/4370996/normal_5f8b75f59c154.pdf
- https://cdn-cms.f-static.net/uploads/4375357/normal_5f8954dab6707.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- pevugubak.weebly.com
- kikuvabafot.weebly.com
- genigudepa.weebly.com
- vibebivenef.weebly.com
- xesaranit.weebly.com
- buveziketi.weebly.com
- degujipimisa.weebly.com
- juragubiv.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report