SUSPICIOUS — fe7fd7ddc34.pdf
SUSPICIOUS — fe7fd7ddc34.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e5742f7584974a127088dc9863b3df1f3b93589ad2aaf56ca23d88646fb97612 - SHA-1:
f094276cf4df63e601b69b3a9182a1f0eda82515 - MD5:
03723130c61d4c6b20f96af26d8de0bf - ssdeep:
768:ygGzpDRpwoAPdK8zkVlSy604IuAmv7B+0zT6xnnvYc17aT+Wlp5ZAERsT5:vGFlpwprzBrTonvP1clp5ZJRsT5 - TLSH:
T155319EF340E7ED8DBB8A9B57EDE6109A5149D38C6022EBA0549D772DD8BC1FD2E00811 - Submitted as: fe7fd7ddc34.pdf
- File type: pdf · Size: 43133 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=bachata%20dominicana%202018, https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf, https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/kolapabajiritu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=bachata%20dominicana%202018
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/kolapabajiritu.pdf
- https://jivexine.weebly.com/uploads/1/3/1/3/131380908/zoselapageve.pdf
- https://fulipevaxavu.weebly.com/uploads/1/3/2/6/132695351/397400.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/3649022.pdf
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f87c2076827d.pdf
- https://site-1041587.mozfiles.com/files/1041587/11073642591.pdf
- https://site-1039355.mozfiles.com/files/1039355/98127135893.pdf
- https://site-1037283.mozfiles.com/files/1037283/98880538206.pdf
- https://site-1042926.mozfiles.com/files/1042926/tagiregozuzorizewe.pdf
- https://site-1043042.mozfiles.com/files/1043042/dokewazivufoxadojumigebi.pdf
- https://cdn.shopify.com/s/files/1/0432/6899/7286/files/converter_to_word_offline_free.pdf
- https://cdn.shopify.com/s/files/1/0477/4677/7244/files/35553362867.pdf
- https://cdn.shopify.com/s/files/1/0498/5936/2973/files/nc_high_school_credits_for_graduation.pdf
- https://cdn.shopify.com/s/files/1/0430/4302/9143/files/hotspot_shield_cracked_apk_android.pdf
- https://cdn.shopify.com/s/files/1/0496/4886/1333/files/38499703823.pdf
- https://cdn.shopify.com/s/files/1/0499/9443/2667/files/azar_fundamentals_of_english_grammar_workbook.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f87f2aa683c3.pdf
- https://cdn-cms.f-static.net/uploads/4366664/normal_5f87865b23ebb.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f87042be6661.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f877bb8804f8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- jawasolasazilem.weebly.com
- wonigebegi.weebly.com
- jivexine.weebly.com
- fulipevaxavu.weebly.com
- pumowurunumig.weebly.com
- cdn-cms.f-static.net
- site-1041587.mozfiles.com
- site-1039355.mozfiles.com
- site-1037283.mozfiles.com
- site-1042926.mozfiles.com
- site-1043042.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report