SUSPICIOUS — eae32334e2a30.pdf
SUSPICIOUS — eae32334e2a30.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
cd96926047a9026684463092ddf3147808631eb180016ca3fdd7982a9154d674 - SHA-1:
beb8f68b665b6df0f98a232db6597eb2e94e1b82 - MD5:
9e110467b82dafa0da11150a49a6e4aa - ssdeep:
3072:8F7p6f3wBWeTz07bjxJvp9FV5N8jdHbCYK/UDlLZmv0PHzcQgw0ZqBVefMiWS1:0N6TeTz07bx9P5kdHbCsDlVmMPHzpgwI - TLSH:
T1684002F710AFEC9C3AAECB23A97E05AD148692C4B12747601058D73DC0BD7AE7E20194 - Submitted as: eae32334e2a30.pdf
- File type: pdf · Size: 171611 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=gta%20all%20gta%20vice%20city%20cheats%20pdf%20download, https://rowurasivove.weebly.com/uploads/1/3/4/3/134357219/zofofub.pdf, https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/jafunofazekobozefana.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=gta%20all%20gta%20vice%20city%20cheats%20pdf%20download
- https://rowurasivove.weebly.com/uploads/1/3/4/3/134357219/zofofub.pdf
- https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/jafunofazekobozefana.pdf
- https://kilejotiwig.weebly.com/uploads/1/3/1/4/131406519/bepokorinoxabiv.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/kezanerodewukew-sijulamigikizox-vutugimun.pdf
- https://norumevi.weebly.com/uploads/1/3/0/9/130969469/390da6f8aad9ed.pdf
- https://xonuvalax.weebly.com/uploads/1/3/1/4/131437330/tapar.pdf
- https://purigimotefejis.weebly.com/uploads/1/3/4/3/134308192/51fc8cb66ef077b.pdf
- https://vunixumo.weebly.com/uploads/1/3/1/4/131453253/generanufadipo.pdf
- https://s3.amazonaws.com/fasanag/beltenebros_antonio_muoz_molina.pdf
- https://s3.amazonaws.com/henghuili-files2/46444780826.pdf
- https://s3.amazonaws.com/fovezewi/12247204099.pdf
- https://s3.amazonaws.com/fasanag/tajanijeridozekuk.pdf
- https://s3.amazonaws.com/votuweroxigezog/movafejoxeselotofo.pdf
- https://s3.amazonaws.com/zarusegibitumet/human_behaviour_psychology_books_in_hindi.pdf
- https://s3.amazonaws.com/rizezobabub/bilaw.pdf
- https://s3.amazonaws.com/bokelur/automatisme_programmable_industriel.pdf
- https://s3.amazonaws.com/dusubonifu/pensar_la_arquitectura_peter_zumthor_descargar.pdf
- https://s3.amazonaws.com/desenaz/rovudoxipakuwab.pdf
- https://cdn-cms.f-static.net/uploads/4366324/normal_5f87165a4fee5.pdf
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f914de155612.pdf
- https://cdn-cms.f-static.net/uploads/4368735/normal_5f915d9762066.pdf
- https://cdn-cms.f-static.net/uploads/4379726/normal_5f967a499dc87.pdf
- https://cdn-cms.f-static.net/uploads/4383444/normal_5f957126e0ed4.pdf
- https://s3.amazonaws.com/tokafanawa/abituriyent_jurnali_5_2019.pdf
Embedded domains
- cctraff.ru
- rowurasivove.weebly.com
- fotejisatowonu.weebly.com
- kilejotiwig.weebly.com
- dutitujazekap.weebly.com
- norumevi.weebly.com
- xonuvalax.weebly.com
- purigimotefejis.weebly.com
- vunixumo.weebly.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- b:\@~
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report