SUSPICIOUS — d5aa741f161b8.pdf
SUSPICIOUS — d5aa741f161b8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e5427749c8bbcf5d477597f88bbad362d26028176bd808b10504372ec172634a - SHA-1:
f15d0dbd7deea2ac649e9eccbff979b6bdd3dea1 - MD5:
abe1c82cefe88831d27b6a1f16661ac3 - ssdeep:
768:BgGzpD3pnrnlArjLolrqVtYIxRkocuU1dO3iI3ABFHEg30JgKEt:yGFjpnr7IYvF71dOSpNEJgKEt - TLSH:
T146327CF35097ED8C7A8B6F1BEAE61458508AD349603A97E054887B2DC47CAFD7F10920 - Submitted as: d5aa741f161b8.pdf
- File type: pdf · Size: 47448 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=rubik, https://cdn-cms.f-static.net/uploads/4366377/normal_5f870ec1ba015.pdf, https://cdn-cms.f-static.net/uploads/4366949/normal_5f874edb7378a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=rubik
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f870ec1ba015.pdf
- https://cdn-cms.f-static.net/uploads/4366949/normal_5f874edb7378a.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f87154d4d9e8.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f876aa8ae016.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f8741180325e.pdf
- https://site-1040427.mozfiles.com/files/1040427/jinimadinokidokobobijug.pdf
- https://site-1043545.mozfiles.com/files/1043545/naxeduvubadipezami.pdf
- https://site-1039314.mozfiles.com/files/1039314/famijugada.pdf
- https://site-1039529.mozfiles.com/files/1039529/2834597043.pdf
- https://site-1041405.mozfiles.com/files/1041405/9198524553.pdf
- https://uploads.strikinglycdn.com/files/c239e5ab-23e7-424e-b844-1c1ed5a2cd26/53962449818.pdf
- https://uploads.strikinglycdn.com/files/5508d41e-6ab3-4561-9bf6-0d3e005a8706/20666542311.pdf
- https://uploads.strikinglycdn.com/files/8c79b060-e91d-4871-9910-b3795d049e33/tifidivev.pdf
- https://uploads.strikinglycdn.com/files/4c88e0c0-322b-4714-9310-945d30c317e9/xukagadifirekota.pdf
- https://uploads.strikinglycdn.com/files/255d100e-d603-42d2-9f72-692d356b9592/23760544750.pdf
- https://uploads.strikinglycdn.com/files/1d857ea3-0fcf-4b9d-bd6f-81e6d215aff5/fevisanixesanozamanesap.pdf
- https://uploads.strikinglycdn.com/files/f4385bdf-a3a5-4f56-96b9-20ae60e2f9ad/10463940860.pdf
- https://uploads.strikinglycdn.com/files/b8d00402-4a2c-499c-a2e7-fed343010715/livupanefifevabofadixales.pdf
- https://uploads.strikinglycdn.com/files/a6e23385-75aa-4231-804f-81418eb9353e/vatubake.pdf
- https://uploads.strikinglycdn.com/files/4be8ff6a-4d31-47c7-a182-6adccee414ff/68090702750.pdf
- https://uploads.strikinglycdn.com/files/47cadda2-b9b1-4b9a-980c-acadc3bd3847/wuramowe.pdf
- https://uploads.strikinglycdn.com/files/f4943946-0902-43da-9467-073b90ec3203/tebiwanivixovipepij.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1040427.mozfiles.com
- site-1043545.mozfiles.com
- site-1039314.mozfiles.com
- site-1039529.mozfiles.com
- site-1041405.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report