SUSPICIOUS — 896edcc73.pdf
SUSPICIOUS — 896edcc73.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b979eaeb4f3400453a7a00aafd19f372ab9797ce98b52b4f93d9444345427839 - SHA-1:
26a13b21460f099eee282639d6503d7786810479 - MD5:
f7b5036ad45d1583a14a645fce50d380 - ssdeep:
768:8gGzpD9AMvOhNH+V3QgvPgmL5sxWZNDGlaVvYR9uEo1U:ZGFxFxQg3LL5sxWZNagvYHudU - TLSH:
T12C318DF35097DD8C7A8BAB53A9F21554228AC74D70329B6044C8BA6DC4BC2BC7F10E90 - Submitted as: 896edcc73.pdf
- File type: pdf · Size: 41969 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafficel.ru/wb?keyword=ocean%20studies%20investigation%20manual, https://uploads.strikinglycdn.com/files/2cd45237-b9d2-4417-9cf2-47dcc45d9294/25720467466.pdf, https://uploads.strikinglycdn.com/files/6a0c4b29-19c9-432b-aa76-8d5f8b4e457e/95405243356.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/wb?keyword=ocean%20studies%20investigation%20manual
- https://uploads.strikinglycdn.com/files/2cd45237-b9d2-4417-9cf2-47dcc45d9294/25720467466.pdf
- https://uploads.strikinglycdn.com/files/6a0c4b29-19c9-432b-aa76-8d5f8b4e457e/95405243356.pdf
- https://denijebif.weebly.com/uploads/1/3/4/5/134584122/c2a2d.pdf
- https://uploads.strikinglycdn.com/files/06b68844-3a52-406f-94f0-c70c09043de9/zelemofoposufafu.pdf
- https://uploads.strikinglycdn.com/files/e59c4c0f-9dc2-451d-b9a2-9101c6c038d7/canto_general_pablo_neruda.pdf
- https://uploads.strikinglycdn.com/files/4859d36f-88ee-4d23-9ce4-78d91e61fa12/zodexuvuvaz.pdf
- https://cdn-cms.f-static.net/uploads/4393911/normal_5f92435d675e5.pdf
- https://cdn-cms.f-static.net/uploads/4374983/normal_5f8d03fb8c94f.pdf
- https://uploads.strikinglycdn.com/files/f26675ac-ca64-4880-99e4-810022b7fc6d/vogibavazamafelutikutopa.pdf
- https://uploads.strikinglycdn.com/files/ca087ec9-7473-46fa-942c-11f7cf8ccc3c/7103106712.pdf
- https://uploads.strikinglycdn.com/files/4942ec3c-7ef5-4983-8c3f-48501b082e00/naxibabib.pdf
- https://uploads.strikinglycdn.com/files/dd2c1a1d-7bd6-43aa-bb2d-1317820a4686/lekokiwulaxe.pdf
- https://cdn-cms.f-static.net/uploads/4391308/normal_5f97e3009fbde.pdf
- https://muwegejise.weebly.com/uploads/1/3/4/2/134265646/7b75c5e65c.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- uploads.strikinglycdn.com
- denijebif.weebly.com
- cdn-cms.f-static.net
- muwegejise.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report