SUSPICIOUS — bac919bf64c5.pdf
SUSPICIOUS — bac919bf64c5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e00f75155985fcb5a4c75879c2da770e48a8957bd03869f8d8b5a27753214873 - SHA-1:
87583b4369b6550822cbc6f04f3f684ac898629b - MD5:
bc5bc0a1bf95276a17f6bcdcf930e662 - ssdeep:
768:kNgGzpDdp8fhsgkOunhdTxfahBH/bJgLhQlNhxicB4JSYT2i3MD2yj7M5pW:kuGFxp8pshbfoBK9QfyT2i3lyfCW - TLSH:
T17B33ADF38497EC8CBE9ACB036DAB21564189838C613393A04959B72DC4FC5FDBE54960 - Submitted as: bac919bf64c5.pdf
- File type: pdf · Size: 47819 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=og%20word%20family%20worksheets%20for%20kindergarten, https://site-1048245.mozfiles.com/files/1048245/sesewosar.pdf, https://site-1040326.mozfiles.com/files/1040326/34249208918.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=og%20word%20family%20worksheets%20for%20kindergarten
- https://site-1048245.mozfiles.com/files/1048245/sesewosar.pdf
- https://site-1040326.mozfiles.com/files/1040326/34249208918.pdf
- https://site-1039538.mozfiles.com/files/1039538/fijugisezenozezevitejev.pdf
- https://site-1037204.mozfiles.com/files/1037204/mejapu.pdf
- https://uploads.strikinglycdn.com/files/b16f8c73-ed4b-4553-b61a-ec1bc18c8e88/609293652.pdf
- https://site-1038908.mozfiles.com/files/1038908/xajisiwafopiselawo.pdf
- https://site-1042607.mozfiles.com/files/1042607/53666336675.pdf
- https://cdn.shopify.com/s/files/1/0431/7744/3483/files/hamilton_beach_iron_19701_manual.pdf
- https://cdn.shopify.com/s/files/1/0429/5104/9370/files/67689775068.pdf
- https://cdn.shopify.com/s/files/1/0483/5957/1609/files/nowoso.pdf
- https://cdn.shopify.com/s/files/1/0484/8890/6902/files/36817064386.pdf
- https://cdn.shopify.com/s/files/1/0430/3876/9303/files/septic_tank_repair_company.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3355978.pdf
- https://naroxelilokatud.weebly.com/uploads/1/3/1/3/131384214/fukik.pdf
- https://zoxaminajoge.weebly.com/uploads/1/3/1/6/131637873/doginoxitexeret.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/lekofexeb-liwabuwidis-xegakubavut-lanagagiwodu.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/5d6f2da.pdf
- https://fisotewefupug.weebly.com/uploads/1/3/1/0/131071176/fusipuwu-suxolumifafidew-xijefulekibiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- site-1048245.mozfiles.com
- site-1040326.mozfiles.com
- site-1039538.mozfiles.com
- site-1037204.mozfiles.com
- uploads.strikinglycdn.com
- site-1038908.mozfiles.com
- site-1042607.mozfiles.com
- cdn.shopify.com
- gimejexoxixaza.weebly.com
- naroxelilokatud.weebly.com
- zoxaminajoge.weebly.com
- dutitujazekap.weebly.com
- tivakoxidedopa.weebly.com
- keniwuki.weebly.com
- fisotewefupug.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report