SUSPICIOUS — 748a1d.pdf
SUSPICIOUS — 748a1d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f06a69ffe2d391afd760eaff411377b04dfe2aec5748c4e20a2ab54f8053cbd7 - SHA-1:
df67128c06836c05b5f4c7a3a54653be4d0e0cd2 - MD5:
82e9db07da7c511e1a290309d6186ecb - ssdeep:
384:isFlS3K6XgKV7cAgdOpW+0cbAJS5l1vrkOuQ/gYBdEqvm/bgEon7Affos+ZmyK/a:CgGzpDzMSLuMdEnEZBZm1LM763PH/E - TLSH:
T13F318EF32057DC4C7A877B039EB61459609AC6497022976024DCBB7CD0BCAFDAE41E61 - Submitted as: 748a1d.pdf
- File type: pdf · Size: 39329 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=free%20online%20proxy%20sites%202020, https://tadazumagitose.weebly.com/uploads/1/3/3/9/133987040/1183581.pdf, https://uploads.strikinglycdn.com/files/895751d9-5bba-4c67-958d-a8a120890a4f/tuzanusozemewedafoduj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=free%20online%20proxy%20sites%202020
- https://tadazumagitose.weebly.com/uploads/1/3/3/9/133987040/1183581.pdf
- https://s3.amazonaws.com/roxawo/sojanax.pdf
- https://uploads.strikinglycdn.com/files/895751d9-5bba-4c67-958d-a8a120890a4f/tuzanusozemewedafoduj.pdf
- https://uploads.strikinglycdn.com/files/021e7a41-2cc7-43f8-9a53-6eda3fd2f47d/98436072442.pdf
- https://texitanoz.weebly.com/uploads/1/3/0/7/130739996/zananadag_momazeji_zosud_raxejagemedi.pdf
- https://uploads.strikinglycdn.com/files/1106fbc1-4a09-4d03-bd4b-9c97ef525686/wuwabeji.pdf
- https://uploads.strikinglycdn.com/files/c8747d85-94a4-4281-848a-593a979489e2/buy_cigarettes_online.pdf
- https://uploads.strikinglycdn.com/files/f05da13c-f91b-4eab-98f5-87cb1837bc26/serrano_pepper_scoville_units.pdf
- https://rokumetusemep.weebly.com/uploads/1/3/4/3/134382705/dudabukifupaf-lufelaba.pdf
- https://cdn-cms.f-static.net/uploads/4370055/normal_5f8e06759569c.pdf
- https://uploads.strikinglycdn.com/files/ed38da96-5a5f-4b3f-a800-33bfb4b5ddda/89791561282.pdf
- https://bujegeti.weebly.com/uploads/1/3/4/3/134355457/sanuxaz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- tadazumagitose.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- texitanoz.weebly.com
- rokumetusemep.weebly.com
- cdn-cms.f-static.net
- bujegeti.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report