SUSPICIOUS — 12931c3868.pdf
SUSPICIOUS — 12931c3868.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
99d56bf5520a82377d8918f3979bde9a613de92264ae46ca04515c43aa50da34 - SHA-1:
f6a12065c015f4f6ef70f2046fbd1ca3e77ea207 - MD5:
d50ca1355da5d6fc339f74e9c5d09164 - ssdeep:
768:9gGzpDJpFdYGf2nuU3nThLZLeygR49ePNv4XsmnPgqUQ9kX4M:+GFtpsD31tLe7RwsNQXTnP2skX4M - TLSH:
T185307CF301D7ED4C7ACA8B03EDAB2999A185D78D913397608898772CD4BC67D6F10860 - Submitted as: 12931c3868.pdf
- File type: pdf · Size: 39118 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=american%20red%20cross%20first%20aid%20manual, https://site-1048572.mozfiles.com/files/1048572/gatumuli.pdf, https://site-1040399.mozfiles.com/files/1040399/71050203602.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=american%20red%20cross%20first%20aid%20manual
- https://site-1048572.mozfiles.com/files/1048572/gatumuli.pdf
- https://site-1040399.mozfiles.com/files/1040399/71050203602.pdf
- https://site-1044145.mozfiles.com/files/1044145/app_kingroot_para_android_6_0.pdf
- https://site-1042548.mozfiles.com/files/1042548/kuxeruzosowaselunun.pdf
- https://site-1038872.mozfiles.com/files/1038872/78523489564.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/6023986.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/9402018.pdf
- https://wegupufula.weebly.com/uploads/1/3/0/8/130813429/8e6285e36d.pdf
- https://pobezewimo.weebly.com/uploads/1/3/2/6/132681951/fidelova-fegubi-wepizosawib-fijiwigerulub.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/pejajofedaxevaw_kozadesupuke.pdf
- https://xufolonul.weebly.com/uploads/1/3/2/6/132695880/24695.pdf
- https://kufazijofiw.weebly.com/uploads/1/3/0/7/130776126/zebagafenis.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/9232432.pdf
- https://cdn.shopify.com/s/files/1/0437/6199/1841/files/lion_king_comic_book.pdf
- https://cdn.shopify.com/s/files/1/0439/3009/1688/files/morop.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/likanutavorolebonat.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/minogewujo_vigura_jukujuxegebukaw.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/jazapoxutob.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/divili_dapixi.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/6431815.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/2556250.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- site-1048572.mozfiles.com
- site-1040399.mozfiles.com
- site-1044145.mozfiles.com
- site-1042548.mozfiles.com
- site-1038872.mozfiles.com
- genigudepa.weebly.com
- zimiduninu.weebly.com
- wegupufula.weebly.com
- pobezewimo.weebly.com
- guwomenod.weebly.com
- xufolonul.weebly.com
- kufazijofiw.weebly.com
- jawasolasazilem.weebly.com
- cdn.shopify.com
- jakedekokobara.weebly.com
- kelobutino.weebly.com
- tejigenunonim.weebly.com
- babikovinemixe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report