SUSPICIOUS — f056b0.pdf
SUSPICIOUS — f056b0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
f6741183c03a73e76592f2272f9746c476e76d55bc0ce278561a49abc0d5c60a - SHA-1:
fb21b21ad290299b2624fe9fce8328e5d6dab2c2 - MD5:
1aadfc395cdad75a49854c59526057fc - ssdeep:
768:jgGzpDNpVIKJpvznWAolqc9W+q+tnLnN4asMYt1muTfVXPHqXSsbg:cGFhpVIyz5cIF+BJ4asdfDVXvqXZg - TLSH:
T19E327CF30097ED8D768B9B036DEA14AA568ED38C7132D7A0588C772DC0BC5AD7E10961 - Submitted as: f056b0.pdf
- File type: pdf · Size: 43403 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=area%202d%20shapes%20worksheet, https://pirizujimo.weebly.com/uploads/1/3/4/4/134454944/1490409.pdf, https://xawiwewediwo.weebly.com/uploads/1/3/4/0/134017039/49a9573c5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=area%202d%20shapes%20worksheet
- https://pirizujimo.weebly.com/uploads/1/3/4/4/134454944/1490409.pdf
- https://xawiwewediwo.weebly.com/uploads/1/3/4/0/134017039/49a9573c5.pdf
- https://nabisipiguges.weebly.com/uploads/1/3/4/4/134432296/ff8cf1fd59.pdf
- https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/4546498.pdf
- https://uploads.strikinglycdn.com/files/5fad4afb-553e-4dff-94b7-93d6be394f24/badusurozaluzun.pdf
- https://uploads.strikinglycdn.com/files/15245e95-8f94-4a1a-b0b1-686cf6c8cf60/69330375595.pdf
- https://uploads.strikinglycdn.com/files/96af5bef-6214-40e5-bd92-c762721b4a92/frozen_full_movie_free_123movies.pdf
- https://s3.amazonaws.com/gulapore/macromedia_dreamweaver_8_tutorial.pdf
- https://s3.amazonaws.com/sojaxub/88696456253.pdf
- https://s3.amazonaws.com/jinabom/71577449276.pdf
- https://uploads.strikinglycdn.com/files/19cd8b42-bc1b-40a4-ac11-bcc85a8c1de9/33066894973.pdf
- https://uploads.strikinglycdn.com/files/ec28f46f-b550-4a44-b3f8-1b79551f376f/ley_de_biot.pdf
- https://uploads.strikinglycdn.com/files/ed62f090-b66e-4ce0-a99b-81f7b37bf1df/exercicios_termodinamica_projeto_medicina.pdf
- https://uploads.strikinglycdn.com/files/7f0728ad-f03c-4e84-b7d0-4812aa1a11a0/dofurowoxesem.pdf
- https://uploads.strikinglycdn.com/files/7c20993f-0d06-4ebe-9b95-3a09520dea37/76895254116.pdf
- https://uploads.strikinglycdn.com/files/16069538-dfcf-4b70-a7ea-b5e62412d0f7/automatismos_elctricos_con_contactores_documento.pdf
- https://uploads.strikinglycdn.com/files/af4965f2-e8a2-44f9-8c88-bbb7ca53c0a4/vibugekoporamefaw.pdf
- https://uploads.strikinglycdn.com/files/62ec4582-c8d7-45e3-9d80-872da3665694/zifanuxuvonemegasaza.pdf
- https://cdn.shopify.com/s/files/1/0492/3057/7817/files/vocaloid_job_plugin.pdf
- https://cdn.shopify.com/s/files/1/0266/9445/1387/files/wiccan_for_beginners.pdf
- https://cdn.shopify.com/s/files/1/0481/6250/4855/files/peace_lutheran_preschool_waunakee.pdf
- https://cdn.shopify.com/s/files/1/0502/2217/0305/files/jororinaromowini.pdf
- https://cdn.shopify.com/s/files/1/0431/0315/8433/files/aps_2019_calendar.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- pirizujimo.weebly.com
- xawiwewediwo.weebly.com
- nabisipiguges.weebly.com
- zegojipoxe.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- M:\l;Q3
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report