SUSPICIOUS — 6625b32.pdf
SUSPICIOUS — 6625b32.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9b0ed4e8c8a4ba1edbefeccd7e08a52eb90a65158f68c1c2ae03b3d8174f47fd - SHA-1:
648ccb576feb341a43852ca6a8888aa35349909a - MD5:
0487c9d1dd6d0bdd572b5beed3bc4850 - ssdeep:
1536:zGFJeS54/DJEpzkqSBxAlTxt/45oP6lPkOcLs5ut7pfk8C:CFJeS54cFS7AF85i4kBLs56Y - TLSH:
T17035AFF710A7DC8C75CB9B03AEAB2559544AC3486133AB6049887B6CC4BC3BD3F41A91 - Submitted as: 6625b32.pdf
- File type: pdf · Size: 63036 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=mcculloch%20chainsaw%20service%20manual, https://cdn-cms.f-static.net/uploads/4405929/normal_5f91fe36b564b.pdf, https://cdn-cms.f-static.net/uploads/4389080/normal_5f912c9c66b18.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=mcculloch%20chainsaw%20service%20manual
- https://cdn-cms.f-static.net/uploads/4405929/normal_5f91fe36b564b.pdf
- https://cdn-cms.f-static.net/uploads/4389080/normal_5f912c9c66b18.pdf
- https://cdn-cms.f-static.net/uploads/4369494/normal_5f8a569492ea0.pdf
- https://cdn-cms.f-static.net/uploads/4377647/normal_5f8ac42b77fc2.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f89dfdbba2b3.pdf
- https://cdn-cms.f-static.net/uploads/4371025/normal_5f8eed4e4c156.pdf
- https://cdn-cms.f-static.net/uploads/4411503/normal_5f93e867aa3ff.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f8c931758e69.pdf
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f8a2bef30d43.pdf
- https://uploads.strikinglycdn.com/files/b7057734-a8e1-4c10-bb94-0308a325e5bd/14326029137.pdf
- https://uploads.strikinglycdn.com/files/e80c083f-dd28-4b46-8aa9-7995e3029a8d/59620964930.pdf
- https://uploads.strikinglycdn.com/files/b3cdcb6d-c8e0-4d69-a87c-fbf1bfe4be69/natuxapeterewos.pdf
- https://uploads.strikinglycdn.com/files/0829f91c-1ce8-47fd-b1b2-bbe89ea9540c/right_triangle_review_worksheet_answer_key.pdf
- https://uploads.strikinglycdn.com/files/2e250877-4a58-4c06-8c86-1cbe40d63ec6/61796686222.pdf
- https://pepisukuwen.weebly.com/uploads/1/3/1/6/131606293/3f1fe3bbb2.pdf
- https://niresofet.weebly.com/uploads/1/3/2/6/132682193/1648511.pdf
- https://rowurasivove.weebly.com/uploads/1/3/4/3/134357219/vixex.pdf
- https://fonaduwi.weebly.com/uploads/1/3/4/3/134366998/3071989.pdf
- https://bituxusod.weebly.com/uploads/1/3/4/3/134347303/1675054.pdf
- https://dufejubodumafeb.weebly.com/uploads/1/3/4/4/134444341/f749a798b.pdf
- https://temazojirilezin.weebly.com/uploads/1/3/2/3/132302863/jedejetimase.pdf
- https://s3.amazonaws.com/zetare/petudepaso.pdf
- https://s3.amazonaws.com/fotojipifuzitul/woguwuzojivuwalavitof.pdf
- https://s3.amazonaws.com/fusidejebi/activator_methods_protocol.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- pepisukuwen.weebly.com
- niresofet.weebly.com
- rowurasivove.weebly.com
- fonaduwi.weebly.com
- bituxusod.weebly.com
- dufejubodumafeb.weebly.com
- temazojirilezin.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report