SUSPICIOUS — e1667a87f71a7.pdf
SUSPICIOUS — e1667a87f71a7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
dbdc4ce5da4f2c893370ea6b4ae6a16040a244abf254b6634e1adbdb09e307ad - SHA-1:
22608073fc093ac1d3dcd3d0896a7b7117977bec - MD5:
479b836fe3fe13765fdb2cded1174d3a - ssdeep:
1536:yGF7puMgkVJbT98mUL2Es64mMmUhcJY+BcR1zlB:rF7puMgkVhT98mUq8W+BcR1T - TLSH:
T1EE35AEF350A7DD8E3A8B9F13AE9B2959A049D74DA132E660008D366CC0BC77C7F54821 - Submitted as: e1667a87f71a7.pdf
- File type: pdf · Size: 57781 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=cleanflight%20upgrade%20firmware%20cli, https://cdn-cms.f-static.net/uploads/4365998/normal_5f8734b2dcd15.pdf, https://cdn-cms.f-static.net/uploads/4366344/normal_5f870dab5268c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=cleanflight%20upgrade%20firmware%20cli
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8734b2dcd15.pdf
- https://cdn-cms.f-static.net/uploads/4366344/normal_5f870dab5268c.pdf
- https://cdn-cms.f-static.net/uploads/4368486/normal_5f893bfda26e2.pdf
- https://cdn.shopify.com/s/files/1/0434/9699/7030/files/westglades_middle_school_teachers.pdf
- https://cdn.shopify.com/s/files/1/0430/8526/7097/files/desilej.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/zutilipevozafeguwu.pdf
- https://jivexine.weebly.com/uploads/1/3/1/3/131380908/vokuzamik.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f873c09b4108.pdf
- https://cdn-cms.f-static.net/uploads/4367289/normal_5f873bd659bdb.pdf
- https://cdn-cms.f-static.net/uploads/4377908/normal_5f8a5dcb76df2.pdf
- https://cdn-cms.f-static.net/uploads/4373999/normal_5f8977a40136a.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ratot_muweliwamopoj.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/1429013.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/maladafowerosuna.pdf
- https://zusaneji.weebly.com/uploads/1/3/0/8/130813769/guzefonugumabaw.pdf
- https://cdn-cms.f-static.net/uploads/4371497/normal_5f8a1c6366542.pdf
- https://cdn-cms.f-static.net/uploads/4379841/normal_5f8a90a25e057.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- guwomenod.weebly.com
- jivexine.weebly.com
- gevafitasib.weebly.com
- tivakoxidedopa.weebly.com
- zusaneji.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report