SUSPICIOUS — f5bb35d255c76.pdf
SUSPICIOUS — f5bb35d255c76.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e9e5de60b92bf8f302409f53f9cf40d02ccc437f7c59bdf43f146c007996045e - SHA-1:
2454986b9ed9e61fae7f5afd6f40966754980faa - MD5:
51c6509a0f3fda9fbc7a046df8ff99c6 - ssdeep:
768:ygGzpDYqwdThGZDZa4dcj+8GDZaWWPJQ1yfs/wGlFRX9N:vGF80mjZigPJQ14awmFRX9N - TLSH:
T1BE318DF320ABDC8CBA8A9F076DF6285AA589C78D6033D650459C276DC0BC5BDBF01815 - Submitted as: f5bb35d255c76.pdf
- File type: pdf · Size: 41762 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=air%20pollution%20control%20a%20design%20approach%20cooper%20pdf, https://mosodujisar.weebly.com/uploads/1/3/0/7/130739504/9945949.pdf, https://xalipifizipig.weebly.com/uploads/1/3/1/3/131379045/e5881c344.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=air%20pollution%20control%20a%20design%20approach%20cooper%20pdf
- https://mosodujisar.weebly.com/uploads/1/3/0/7/130739504/9945949.pdf
- https://xalipifizipig.weebly.com/uploads/1/3/1/3/131379045/e5881c344.pdf
- https://s3.amazonaws.com/tadovu/avadhanulu_and_kshirsagar-_engineering_physics_free.pdf
- https://uploads.strikinglycdn.com/files/418be5e4-ed9d-4169-88ab-2874d8bb8eca/error_code_lookup_xbox.pdf
- https://uploads.strikinglycdn.com/files/0dd879f0-d283-4cb6-8e70-bf35b1946fad/beechcraft_musketeer_a23_maintenance_manual.pdf
- https://uploads.strikinglycdn.com/files/0d09a6ce-af69-4b2f-9e59-8b6f960cc3dc/guguxizo.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/bavotifa.pdf
- https://gimelukisisira.weebly.com/uploads/1/3/4/0/134040832/gajiwuguwerilewoxab.pdf
- https://peketavapi.weebly.com/uploads/1/3/4/3/134331612/9e2f9c99cd4da16.pdf
- https://junoxavod.weebly.com/uploads/1/3/1/3/131384771/mafogovuxagivelite.pdf
- https://uploads.strikinglycdn.com/files/49f3c600-543e-4f39-8e4b-b50b4af19314/13245149171.pdf
- https://cdn.shopify.com/s/files/1/0438/6878/2757/files/gta_v_mod_apk_android_1.pdf
- https://wagimudo.weebly.com/uploads/1/3/4/4/134475497/tukajofineduvemag.pdf
- https://cdn.shopify.com/s/files/1/0503/3318/8246/files/filmorago_mod_apk_latest_version_download.pdf
- https://cdn.shopify.com/s/files/1/0432/6037/9286/files/texas_seat_belt_law.pdf
- https://mipirizu.weebly.com/uploads/1/3/2/6/132682564/bizupi.pdf
- https://s3.amazonaws.com/forupokisip/stray_dog_simulator_apk.pdf
- https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/3175599.pdf
- https://cdn.shopify.com/s/files/1/0500/4302/7613/files/satimuguzajifo.pdf
- https://s3.amazonaws.com/xanebavifamopez/aceites_esenciales_young_living.pdf
- https://fobedixosofano.weebly.com/uploads/1/3/4/3/134377241/6098693.pdf
- https://s3.amazonaws.com/susopuzupure/20201907284.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- mosodujisar.weebly.com
- xalipifizipig.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- juragubiv.weebly.com
- gimelukisisira.weebly.com
- peketavapi.weebly.com
- junoxavod.weebly.com
- cdn.shopify.com
- wagimudo.weebly.com
- mipirizu.weebly.com
- wosezobar.weebly.com
- fobedixosofano.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report