SUSPICIOUS — da06fc8.pdf
SUSPICIOUS — da06fc8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
baf0d94785a7de90deb3912e67643dd4663b794ed72170875f0003e30b201471 - SHA-1:
b6a61beafd7ab1fa0a492d9395f3bd9a3c51a56f - MD5:
fdadb9040dc6329940bc1b258af8cbaa - ssdeep:
1536:pGFapTZ0cYTFXEdSBCsAeyaZpCuPunQsW:8FapTZREe7sAeyipC0R - TLSH:
T1DD338DF31093DD8C7B8BBB13ADBA05A9648ED748613397944888776CC4BC5AD7F20990 - Submitted as: da06fc8.pdf
- File type: pdf · Size: 51492 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=film%20chouseishin%20gransazer%20sub%20indo, https://uploads.strikinglycdn.com/files/0e716391-3f2c-4f62-ac8e-4a474df66287/95064001868.pdf, https://uploads.strikinglycdn.com/files/0fd01e87-6fca-40e7-9a17-8117c8fa1c69/nitalijafaruvagubujaba.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=film%20chouseishin%20gransazer%20sub%20indo
- https://uploads.strikinglycdn.com/files/0e716391-3f2c-4f62-ac8e-4a474df66287/95064001868.pdf
- https://uploads.strikinglycdn.com/files/0fd01e87-6fca-40e7-9a17-8117c8fa1c69/nitalijafaruvagubujaba.pdf
- https://uploads.strikinglycdn.com/files/bec614b0-a04d-4bf9-829f-c8ff8a196208/83546424408.pdf
- https://uploads.strikinglycdn.com/files/78080897-1f7d-46df-900f-1973c53fb615/61582222007.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f87807591abe.pdf
- https://cdn-cms.f-static.net/uploads/4368246/normal_5f87fcd3a0f7f.pdf
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f875eb343bd6.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f8700d4e7634.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f8713b8ab069.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f87b46aa04c6.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f87479961195.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f86fedae5354.pdf
- https://cdn-cms.f-static.net/uploads/4368505/normal_5f877e7aef0cb.pdf
- https://site-1037178.mozfiles.com/files/1037178/3998811332.pdf
- https://site-1041858.mozfiles.com/files/1041858/pimemewixizagavilex.pdf
- https://site-1038715.mozfiles.com/files/1038715/detenilinumelu.pdf
- https://site-1043928.mozfiles.com/files/1043928/basic_accounting_in_tally.pdf
- https://uploads.strikinglycdn.com/files/ce049dfa-92f8-4fd2-914a-288040fae69a/90300701554.pdf
- https://uploads.strikinglycdn.com/files/45d78ac7-b1d2-4f9a-b85f-225690c34638/56677656188.pdf
- https://uploads.strikinglycdn.com/files/69e06658-c945-44da-bb93-415c5edd4e5c/tiwanesoti.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdf
- https://meporolokiso.weebly.com/uploads/1/3/2/6/132681401/sekuxugikibebu_nudofigewisamew_jamedidow_temofa.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/6838a798463e.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/8819529.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1037178.mozfiles.com
- site-1041858.mozfiles.com
- site-1038715.mozfiles.com
- site-1043928.mozfiles.com
- keniwuki.weebly.com
- meporolokiso.weebly.com
- jukafubu.weebly.com
- jamuseramomuf.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report