SUSPICIOUS — 75dbf.pdf
SUSPICIOUS — 75dbf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e81cca491cb5257e9b2ec7622cf7a243189b53c11fa0a92eb4597c2fcbdf44e2 - SHA-1:
75b947c92618cf84e4ffb15437425c9f10bd9d07 - MD5:
c45c99cf0cbe32db70b8b9e32021e309 - ssdeep:
768:hgGzpDz3Xhcg5RrFg5L2n5pPrw62efVYz+abwo3OIZoJykXa51hF:SGFfnqg5DaLcVwGVID73OSoFXa5DF - TLSH:
T10F33ACF350ABED8C2EC797036EA7145D651ADB8C7132AA64058C3B6D84BC6BE7E10940 - Submitted as: 75dbf.pdf
- File type: pdf · Size: 48207 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafftec.ru/wb?keyword=gw2%20armorsmithing%20guide%201%20400, https://zanobuxukopul.weebly.com/uploads/1/3/4/6/134678616/dapororufebubofogis.pdf, https://uploads.strikinglycdn.com/files/2a25ee24-7ff3-4d5e-9f42-b91f7fed85b0/medicare_secondary_payer_manual_chapter_2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/wb?keyword=gw2%20armorsmithing%20guide%201%20400
- https://zanobuxukopul.weebly.com/uploads/1/3/4/6/134678616/dapororufebubofogis.pdf
- https://uploads.strikinglycdn.com/files/2a25ee24-7ff3-4d5e-9f42-b91f7fed85b0/medicare_secondary_payer_manual_chapter_2.pdf
- https://uploads.strikinglycdn.com/files/f2fbe022-24ca-4f40-802d-e20fb89946fc/xonumiwumuduboripafatuji.pdf
- https://uploads.strikinglycdn.com/files/46acade7-30ff-411a-85fe-472222cb56ac/pokemon_tcg_online_apk.pdf
- https://uploads.strikinglycdn.com/files/96a3a998-0d70-4e78-abe3-90148a2ecd64/pac_rp5-gm11_wiring.pdf
- https://uploads.strikinglycdn.com/files/d7c0c7dc-f11f-4064-983c-f944b9cf63c9/dd_xanathars_guide_to_everything_download.pdf
- https://uploads.strikinglycdn.com/files/7ac284d6-5d0a-451e-9ad7-2b4663f985b3/kifirovekenetumimawuv.pdf
- https://sowufaxekip.weebly.com/uploads/1/3/2/7/132710719/84be6ca0e.pdf
- https://uploads.strikinglycdn.com/files/aee36436-4ac5-4202-a9c5-fde1a0dc48e1/problemas_matematicos_con_numeros_en.pdf
- https://uploads.strikinglycdn.com/files/323953ff-3500-4742-b1bc-e0622e37afb5/porokedasupegirexu.pdf
- https://kunizemofowirux.weebly.com/uploads/1/3/4/3/134311671/5f00fb8f.pdf
- https://uploads.strikinglycdn.com/files/7c81d437-7989-4ef1-b76c-63f5c7ec9f27/old_testament_quotes_about_death.pdf
- https://morupataniseb.weebly.com/uploads/1/3/4/5/134502176/400133.pdf
- https://meronikam.weebly.com/uploads/1/3/4/7/134705372/2fe780.pdf
- https://uploads.strikinglycdn.com/files/3558cda9-8dfa-4c3a-b8a9-d08b8d94fb57/45305528318.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- zanobuxukopul.weebly.com
- uploads.strikinglycdn.com
- sowufaxekip.weebly.com
- kunizemofowirux.weebly.com
- morupataniseb.weebly.com
- meronikam.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report