SUSPICIOUS — bac6b15f061a8b.pdf
SUSPICIOUS — bac6b15f061a8b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
adbf9f6610a4618e55064eb882ee3fc234289417109438501ff4fe23f435d09b - SHA-1:
478c7178397aa2a3011b258ba127fd294eaa6429 - MD5:
b0d72e0283282c3172fa77fc10bd445d - ssdeep:
1536:HGF/pjRQ77sMC1EVDRii6WfghE9ZzOPhsAoXMCZWsPED/pVut9:mF/pj4jGEVDRii6W4EHyPqlcC/uy - TLSH:
T1D63490F35097ED8C398BAF939DAA115D658AC38C7135AAA000C86F6CC17C6BD7F01A51 - Submitted as: bac6b15f061a8b.pdf
- File type: pdf · Size: 54533 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=gay%20whatsapp%20ciudad%20de%20cabo%20de%20enlac, https://uploads.strikinglycdn.com/files/1cbb67ea-3b56-4855-bf07-09d1291982da/8309405702.pdf, https://uploads.strikinglycdn.com/files/b390d416-dfbd-4ef2-a2bd-1a64b2348deb/39639634476.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=gay%20whatsapp%20ciudad%20de%20cabo%20de%20enlac
- https://uploads.strikinglycdn.com/files/1cbb67ea-3b56-4855-bf07-09d1291982da/8309405702.pdf
- https://uploads.strikinglycdn.com/files/b390d416-dfbd-4ef2-a2bd-1a64b2348deb/39639634476.pdf
- https://uploads.strikinglycdn.com/files/28c634a6-bd38-4c8d-80e2-9c1b5b90eb37/kufedudasofiwakaz.pdf
- https://cdn-cms.f-static.net/uploads/4367937/normal_5f87d5d866e08.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f8ee5a33b94d.pdf
- https://cdn-cms.f-static.net/uploads/4368996/normal_5f8b227501c60.pdf
- https://cdn-cms.f-static.net/uploads/4372721/normal_5f8cfb0a1798c.pdf
- https://s3.amazonaws.com/fasanag/27657177082.pdf
- https://s3.amazonaws.com/henghuili-files2/41058124175.pdf
- https://s3.amazonaws.com/wonoti/gevotuxarulu.pdf
- https://uploads.strikinglycdn.com/files/4715f3ff-2da1-48f0-b5dd-d109372464db/97205285322.pdf
- https://uploads.strikinglycdn.com/files/d04dc1da-ee0e-4c36-9d49-3d76f4543f66/35589612832.pdf
- https://lefedatit.weebly.com/uploads/1/3/0/7/130776734/jakejodezepulo.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/03b622.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/dekojojanuxiras_lawelepebovika_sidej.pdf
- https://fosogaji.weebly.com/uploads/1/3/1/4/131455903/dodosowexobofule.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/favaputuxepe.pdf
- https://tisatazufewuvo.weebly.com/uploads/1/3/1/1/131163687/5452731.pdf
- https://zewubonorow.weebly.com/uploads/1/3/1/3/131398185/0efa7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- lefedatit.weebly.com
- pigogokeda.weebly.com
- papunagaku.weebly.com
- fosogaji.weebly.com
- vimiwegom.weebly.com
- tisatazufewuvo.weebly.com
- zewubonorow.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report