SUSPICIOUS — 51093c4480.pdf
SUSPICIOUS — 51093c4480.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e0e0c766f9dfead6dd88b2209b05f9c6bdb331d5bd1f870b911d543f0a8f5a05 - SHA-1:
9fa07d41450a23b105fbdf8d8313bd79bc3867c3 - MD5:
ed79d6e97a2d451595d4999d95c6f22f - ssdeep:
768:+gGzpDrMr7AaSgm1KajhDiGbC4/ujAkWn1ek3W:7GFXmU3def4/9k8e2W - TLSH:
T178319DF31157ED8C6F8BAF179AA600947146D34E6133A7A004D87BACC8BC2BC2E54970 - Submitted as: 51093c4480.pdf
- File type: pdf · Size: 43086 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=macroeconomic%20policy%20and%20financial%20markets%20pdf, https://uploads.strikinglycdn.com/files/7a5e6e6e-3d22-4d0f-9e03-972c3a86394f/zebes.pdf, https://cdn-cms.f-static.net/uploads/4409602/normal_5f963105a5350.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=macroeconomic%20policy%20and%20financial%20markets%20pdf
- https://s3.amazonaws.com/xukonakefules/xemikazovifol.pdf
- https://uploads.strikinglycdn.com/files/7a5e6e6e-3d22-4d0f-9e03-972c3a86394f/zebes.pdf
- https://cdn-cms.f-static.net/uploads/4409602/normal_5f963105a5350.pdf
- https://cdn-cms.f-static.net/uploads/4415951/normal_5f9ceec649554.pdf
- https://s3.amazonaws.com/nokiva/barking_up_the_wrong_tree_book.pdf
- https://s3.amazonaws.com/pivetuzadujo/what_is_the_purpose_of_writing_a_biography.pdf
- https://uploads.strikinglycdn.com/files/3a2477dd-4b9b-4039-8678-987635ee35d9/97545506915.pdf
- https://uploads.strikinglycdn.com/files/fe1ab57c-ba67-4bb6-bbc3-ebaed81eeef6/raderotato.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/5227012.pdf
- https://radutarogo.weebly.com/uploads/1/3/4/3/134379411/letewimanag.pdf
- https://cdn-cms.f-static.net/uploads/4386366/normal_5f926fb4e4f7f.pdf
- https://s3.amazonaws.com/fezenur/60966906320.pdf
- https://uploads.strikinglycdn.com/files/8ba64444-e5ff-48c6-b715-a16f76e8bab4/mijewimupe.pdf
- https://s3.amazonaws.com/wisuw/pan_card_correction_form_2019_online.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- xawuwotogot.weebly.com
- radutarogo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report