SUSPICIOUS — 54c72e.pdf
SUSPICIOUS — 54c72e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
bb215bf3a041cce6f7f639c6288fc1cc5f323e3258fe07614722cff05c2ba3c9 - SHA-1:
f8e137b253621df5564b1f6b3b1c166456caa961 - MD5:
1fa2bcd53470e8d888003c998ef6c69b - ssdeep:
768:ygGzpD1sVu77jaHyHYTj1vicNH979mtDyFVLhV0suOKAy4epxhjBxPqwhtrY/:vGFxIFdZmVyF6ODepxh1xPq8trY/ - TLSH:
T10233AFF340ABDC4C7A879F13ADB6159A604AD6487133ABA445D9772CC4BC6BCBF10520 - Submitted as: 54c72e.pdf
- File type: pdf · Size: 49062 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=owl%202020%20teams, https://cdn-cms.f-static.net/uploads/4401519/normal_5f9aac95c75e9.pdf, https://cdn-cms.f-static.net/uploads/4372354/normal_5f8b82f7f303c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=owl%202020%20teams
- https://cdn-cms.f-static.net/uploads/4401519/normal_5f9aac95c75e9.pdf
- https://tibepitetuj.files.wordpress.com/2020/11/36426037384.pdf
- https://cdn-cms.f-static.net/uploads/4372354/normal_5f8b82f7f303c.pdf
- https://cdn-cms.f-static.net/uploads/4379233/normal_5f974c913521c.pdf
- https://uploads.strikinglycdn.com/files/011606be-95b7-4f88-ba31-dd7a7b03b641/nusifogezuwavarekumapotan.pdf
- https://uploads.strikinglycdn.com/files/c17e5843-1940-4e0e-a73c-a385bc45570d/geweriwuwazuremadane.pdf
- https://cdn-cms.f-static.net/uploads/4411683/normal_5fa60f375e824.pdf
- https://lodoxepal.files.wordpress.com/2020/11/vibinofa.pdf
- https://wefufepolo.files.wordpress.com/2020/11/en_busca_del_tiempo_perdido_marcel_p.pdf
- https://uploads.strikinglycdn.com/files/88a1408a-fb18-4f5e-90c3-8ace02220f98/forejabanekadatimorodagaf.pdf
- https://cdn-cms.f-static.net/uploads/4421061/normal_5f9a91719b451.pdf
- https://uploads.strikinglycdn.com/files/5221ad45-4685-4554-b759-2494ef8b98e6/12169099007.pdf
- https://cdn-cms.f-static.net/uploads/4426687/normal_5fa0f97a99131.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f872e0b536f2.pdf
- https://uploads.strikinglycdn.com/files/64e0d1a4-bfb6-44ab-968d-7e51f206b4b3/14537491961.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- tibepitetuj.files.wordpress.com
- uploads.strikinglycdn.com
- lodoxepal.files.wordpress.com
- wefufepolo.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report