SUSPICIOUS — 6856298.pdf
SUSPICIOUS — 6856298.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
cedeec85bde570db1962ba2082e66ebb7ac323e7b652b88ef9337cb0edeea93d - SHA-1:
d8d98337a1791d0ab73c01b6914f97868515ed0b - MD5:
0bea9a18456c13725af23d7baedd3769 - ssdeep:
768:HgGzpD7KP0BDY6c5saPsewJOeWZ4IRf6xNBjjQ4J:AGFnUQY6aPse4pjc6xNFjQ4J - TLSH:
T19E319DF35197ED4C3A8A9B135EDB0099A045D3CDB1728B6048D97B6DC8BC2ED6E11822 - Submitted as: 6856298.pdf
- File type: pdf · Size: 42820 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafffi.ru/wb?keyword=ffxi%20pld%20gearswap, https://subefurova.weebly.com/uploads/1/3/4/5/134505332/tegex-tigite-tiwipulowixoro-vivepuwegeripak.pdf, https://romakajesak.weebly.com/uploads/1/3/4/5/134508807/54c72e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/wb?keyword=ffxi%20pld%20gearswap
- https://ganilumigipe.files.wordpress.com/2020/11/rail_ticket_reservation_form.pdf
- https://bebivix.files.wordpress.com/2020/11/silezo.pdf
- https://zevewibomopi.files.wordpress.com/2020/11/jopobetunelid.pdf
- https://subefurova.weebly.com/uploads/1/3/4/5/134505332/tegex-tigite-tiwipulowixoro-vivepuwegeripak.pdf
- https://romakajesak.weebly.com/uploads/1/3/4/5/134508807/54c72e.pdf
- https://pefojefevofat.weebly.com/uploads/1/3/4/6/134659321/ninolajewop.pdf
- https://lekinowi.weebly.com/uploads/1/3/4/4/134476644/velazusuzebojij.pdf
- https://lizuruvinulu.files.wordpress.com/2020/11/skyrim_special_edition_savegame.pdf
- https://dilopipo.files.wordpress.com/2020/11/demetivudaxakoleze.pdf
- https://givolajokofe.files.wordpress.com/2020/11/japatewajaliwififu.pdf
- https://xetibipu.weebly.com/uploads/1/3/4/5/134528590/gazivazamilar.pdf
- https://kipidabivipili.weebly.com/uploads/1/3/4/3/134340994/somimemofu-bazafopojemafib.pdf
- https://gulaxad.files.wordpress.com/2020/11/visual_studio_code_format_powershell.pdf
- https://xopaluwejur.weebly.com/uploads/1/3/1/8/131857284/3606222.pdf
- https://gorujugiximu.files.wordpress.com/2020/11/karipevo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- ganilumigipe.files.wordpress.com
- bebivix.files.wordpress.com
- zevewibomopi.files.wordpress.com
- subefurova.weebly.com
- romakajesak.weebly.com
- pefojefevofat.weebly.com
- lekinowi.weebly.com
- lizuruvinulu.files.wordpress.com
- dilopipo.files.wordpress.com
- givolajokofe.files.wordpress.com
- xetibipu.weebly.com
- kipidabivipili.weebly.com
- gulaxad.files.wordpress.com
- xopaluwejur.weebly.com
- gorujugiximu.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report