SUSPICIOUS — cf9f602737939c.pdf
SUSPICIOUS — cf9f602737939c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
dab8dca6877a9a47b0dc7a3404acd2a0b3b473c5cc72d43a4c1adb633525e984 - SHA-1:
34afc3c242145026bc5f4532def1d8ddbb3f94a4 - MD5:
ee77f68a966c3a387529cf22d2252bdb - ssdeep:
768:ugGzpDYpvyBL/ZIFo38QKCeoQZSDEkF7PSxxCBGvCVNzpyhLMCRGVp0g0z:LGF0pv+6hZWEs7woQv8zpy9qcz - TLSH:
T1B0327CF340A7ED8CBA8AAB579CAA1299608DC34C7136D390448C772DD07C5FE7E109A0 - Submitted as: cf9f602737939c.pdf
- File type: pdf · Size: 47298 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=skyrim%20creation%20kit%20disable%20warnings, https://uploads.strikinglycdn.com/files/9a9cca34-8ec6-4745-a445-f6d161cd49a5/4256252752.pdf, https://uploads.strikinglycdn.com/files/bf940410-502e-4e5a-9da4-4dbdf2b1d136/47739253695.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=skyrim%20creation%20kit%20disable%20warnings
- https://uploads.strikinglycdn.com/files/9a9cca34-8ec6-4745-a445-f6d161cd49a5/4256252752.pdf
- https://uploads.strikinglycdn.com/files/bf940410-502e-4e5a-9da4-4dbdf2b1d136/47739253695.pdf
- https://uploads.strikinglycdn.com/files/6aa2c10c-128a-4d2e-b7fd-dabf24471818/borexevavibutaf.pdf
- https://uploads.strikinglycdn.com/files/a5c4c082-06f0-47e9-b51c-baee160e0633/jafesagonimufupulekupod.pdf
- https://uploads.strikinglycdn.com/files/3407b479-c00e-4a3a-a442-d92456d20e2c/sinivamazonuferulogo.pdf
- https://uploads.strikinglycdn.com/files/db297ab3-3b53-4d51-a89d-6efba67b9c09/9312122238.pdf
- https://uploads.strikinglycdn.com/files/b0380eb5-b7ac-48a9-a40d-118e03a947ee/xulidewelodipisefomejorut.pdf
- https://uploads.strikinglycdn.com/files/c54c19ce-8550-4f26-ac13-76ebf2077471/xepewo.pdf
- https://uploads.strikinglycdn.com/files/6fb4d799-c20a-48e5-b7e0-e1b0a51ebaa4/jiseguxo.pdf
- https://site-1042834.mozfiles.com/files/1042834/sewotilibavipuf.pdf
- https://site-1039490.mozfiles.com/files/1039490/56959588592.pdf
- https://site-1039443.mozfiles.com/files/1039443/pimimojumofexudejafog.pdf
- https://site-1039414.mozfiles.com/files/1039414/84699166633.pdf
- https://site-1042672.mozfiles.com/files/1042672/kidinosexa.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f86f9d694e85.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f8731a1b9454.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f873b92f3664.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f875ff71316d.pdf
- https://cdn-cms.f-static.net/uploads/4368735/normal_5f87a4dbf113e.pdf
- https://uploads.strikinglycdn.com/files/1d33a677-3f6d-411d-9172-1b122b724306/xadejalilokidoketipu.pdf
- https://uploads.strikinglycdn.com/files/09c27cdc-9a94-440b-acdf-d90f6fea2dd5/29217865656.pdf
- https://uploads.strikinglycdn.com/files/d7ddb7fc-244d-42ab-8ad5-a6d46e84f86d/18873082622.pdf
- https://uploads.strikinglycdn.com/files/d602d838-ffd6-43a8-9bbb-c98be66ce791/fimisefiramakimijunavofes.pdf
- https://site-1041206.mozfiles.com/files/1041206/banajebonobapozejoj.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1042834.mozfiles.com
- site-1039490.mozfiles.com
- site-1039443.mozfiles.com
- site-1039414.mozfiles.com
- site-1042672.mozfiles.com
- cdn-cms.f-static.net
- site-1041206.mozfiles.com
- site-1040346.mozfiles.com
- site-1039644.mozfiles.com
- site-1039896.mozfiles.com
- site-1044313.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report