SUSPICIOUS — 30c6cf5687826.pdf
SUSPICIOUS — 30c6cf5687826.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a3ba63c62b7747c66cd0d2774bffae5b47a154058fd16e7b3832ffbd06b07c62 - SHA-1:
7e4ddd8f438ee0325a91c1feb901b8f55748e1ff - MD5:
c45134db8c1194636987b7a23438a62e - ssdeep:
768:XfgGzpD2ZYshPmzvb9fNW3sGEkDT9N/tuM01ng9dKtPtIC8cME3h:YGFiXsRkP9Zt4g9UNGwj3h - TLSH:
T14F319EF360A7CD4D3A86AF177EA611A8714AC78C713397A40488B63CC4B86FD6E51921 - Submitted as: 30c6cf5687826.pdf
- File type: pdf · Size: 43220 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafftec.ru/wb?keyword=espn%20arcade%20basketball%20games%20online, https://cdn-cms.f-static.net/uploads/4369656/normal_5f9f12a51bfd7.pdf, https://uploads.strikinglycdn.com/files/baa73ca2-4e20-404b-8d98-03cd0af857f7/73201696971.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/wb?keyword=espn%20arcade%20basketball%20games%20online
- https://cdn-cms.f-static.net/uploads/4369656/normal_5f9f12a51bfd7.pdf
- https://uploads.strikinglycdn.com/files/baa73ca2-4e20-404b-8d98-03cd0af857f7/73201696971.pdf
- https://cdn-cms.f-static.net/uploads/4384628/normal_5f90eeb189e2c.pdf
- https://gijalexipo.files.wordpress.com/2020/11/puffin_browser_pro_app_ios.pdf
- https://uploads.strikinglycdn.com/files/b000ed1b-34af-4dbc-a5f2-3969377c5772/fufowuzonurikeduvofeveso.pdf
- https://uploads.strikinglycdn.com/files/000a7269-c73a-4fc5-8dd5-f444a9d84530/hindi_alphabet_worksheet.pdf
- https://uploads.strikinglycdn.com/files/8b830dca-f203-4181-b826-58dc8a7820ea/23187279504.pdf
- https://cdn-cms.f-static.net/uploads/4408599/normal_5f98a6675c793.pdf
- https://cdn-cms.f-static.net/uploads/4376101/normal_5f902c7f3d138.pdf
- https://uploads.strikinglycdn.com/files/3adc8331-ea1d-45d7-a573-f254eaa926d5/39488575050.pdf
- https://cdn-cms.f-static.net/uploads/4385206/normal_5f9240bc1f18e.pdf
- https://uploads.strikinglycdn.com/files/b89ffa8f-3f8a-4391-a0cb-743a36c1b4ec/zavuze.pdf
- https://cdn-cms.f-static.net/uploads/4427104/normal_5fa819bee60a7.pdf
- https://cdn-cms.f-static.net/uploads/4375716/normal_5f8bb7c1c1c3f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- gijalexipo.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report