SUSPICIOUS — a0cb48.pdf
SUSPICIOUS — a0cb48.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e2bfe48c5a6cca8ce663e44af108b343cb2e42b0ea395f8fdfc201c8c74c6a78 - SHA-1:
5e8a49b6272d2e0b1054e271ef0dacbee89e33c5 - MD5:
e322ca94a0ca4c49deaf62ef7f5d347d - ssdeep:
768:CgGzpDdp0q0wLblLh7XKLr6qqc/NKTg1D1XtWoo6btKkT72H:fGFJpxJdOLr6q3/NKIptWx68k/2H - TLSH:
T1B6327CF35097EC4CBA8F7B039AEB1569604AD64C3176A7605188772DC4BC6EE3F40A21 - Submitted as: a0cb48.pdf
- File type: pdf · Size: 45834 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=tx%20nr575%20review, https://uploads.strikinglycdn.com/files/05f21ab4-5125-457c-9357-5ddafc8c048d/94198446634.pdf, https://uploads.strikinglycdn.com/files/bccf41ad-5509-4242-b826-92a9c19b3205/rativadagode.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=tx%20nr575%20review
- https://uploads.strikinglycdn.com/files/05f21ab4-5125-457c-9357-5ddafc8c048d/94198446634.pdf
- https://uploads.strikinglycdn.com/files/bccf41ad-5509-4242-b826-92a9c19b3205/rativadagode.pdf
- https://uploads.strikinglycdn.com/files/9a9ee933-1a7f-419e-9487-c6c1100333a9/70040844652.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f873c470afad.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8756ac223f7.pdf
- https://cdn-cms.f-static.net/uploads/4366655/normal_5f872daf24697.pdf
- https://uploads.strikinglycdn.com/files/aed446eb-f2b3-45d0-a029-d90989a60e0b/xifape.pdf
- https://uploads.strikinglycdn.com/files/afe3945a-5b74-4bca-864a-41b134bf329c/43053960056.pdf
- https://uploads.strikinglycdn.com/files/d0118824-b2a1-4cc5-9002-4515d33d6b71/97325861782.pdf
- https://uploads.strikinglycdn.com/files/70a1312f-c0b6-4ec2-b222-e7c6acec6a0b/mabajuzowutovixir.pdf
- https://site-1038682.mozfiles.com/files/1038682/65174972537.pdf
- https://site-1038343.mozfiles.com/files/1038343/95835260444.pdf
- https://uploads.strikinglycdn.com/files/c0f8825b-0336-461a-adec-7e2cda2f5ded/dojemoruturekijalilezo.pdf
- https://uploads.strikinglycdn.com/files/55b1abf1-3fed-45c4-82fc-79b5bd6f2ed7/kiletu.pdf
- https://uploads.strikinglycdn.com/files/51f0a7fb-1f56-4701-b64e-362dbc0f07da/fowenalupoxij.pdf
- https://uploads.strikinglycdn.com/files/6912a0cc-e81b-4c0b-8ad6-b047eaf4edbf/dusajoro.pdf
- https://uploads.strikinglycdn.com/files/833bcc57-0903-471f-97e0-f9d88d3d8a83/sisidupapuxetekiditu.pdf
- https://uploads.strikinglycdn.com/files/18b663fe-d5a3-43c4-9c7f-160ef6c0351f/wudolofip.pdf
- https://uploads.strikinglycdn.com/files/529fc092-0cd2-4560-8238-edc386536858/45925330824.pdf
- https://uploads.strikinglycdn.com/files/767b42d0-6495-4404-a18b-2ee867c8dd59/2370974120.pdf
- https://uploads.strikinglycdn.com/files/9acaf8be-9ab0-456d-92d8-6031bbca91d1/fedaxuzowoxefame.pdf
- https://uploads.strikinglycdn.com/files/4f9b8866-77de-4818-aae0-1752e83c4d1b/xexovogajoninabumorejuge.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1038682.mozfiles.com
- site-1038343.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report