SUSPICIOUS — c0ca0.pdf
SUSPICIOUS — c0ca0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f79e17466daa52cc221071228af0cb6cf2b9b3b9c77803d562efad8eca5458fc - SHA-1:
54ba3a1ed9257212bb65e183ff016ce9d197762e - MD5:
70ceff6661537b8bf2f4c63295611f8a - ssdeep:
768:1gGzpDDvPdmguqAC/9lWyNUXdbMniYXkau5OzLBfFa8zXc:mGFfvPdKC3WMSdwiYXk6xFa8zXc - TLSH:
T124318DF361A7ED9C6B86AF03A9BA146A5049C38C6032E66449CC3B7CC47C5FD7E14860 - Submitted as: c0ca0.pdf
- File type: pdf · Size: 41637 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=video%20downloader%20app%20fire%20tablet, https://uploads.strikinglycdn.com/files/3f91f8fe-cc11-4ca2-a597-1c5a8861ef3c/92713168400.pdf, https://cdn-cms.f-static.net/uploads/4377381/normal_5f8e378935394.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=video%20downloader%20app%20fire%20tablet
- https://s3.amazonaws.com/zizene/82645436130.pdf
- https://s3.amazonaws.com/gavexilatuvitaz/tewakidu.pdf
- https://uploads.strikinglycdn.com/files/3f91f8fe-cc11-4ca2-a597-1c5a8861ef3c/92713168400.pdf
- https://cdn-cms.f-static.net/uploads/4377381/normal_5f8e378935394.pdf
- https://uploads.strikinglycdn.com/files/67378a79-ff55-44b7-8292-84a731bc5c46/zorufafefozixaxupisabime.pdf
- https://cdn-cms.f-static.net/uploads/4410462/normal_5f9622e74f9d1.pdf
- https://uploads.strikinglycdn.com/files/3e83d1b0-df67-4cc8-a359-57ee0c4ce27e/36730221139.pdf
- https://uploads.strikinglycdn.com/files/1010b530-8ae7-40d6-bb29-6ecd593b440b/fesoz.pdf
- https://s3.amazonaws.com/fadedosi/12th_street_catering_reviews.pdf
- https://uploads.strikinglycdn.com/files/a7227362-547d-4313-a0d9-2a48bc70c0c6/sebates.pdf
- https://uploads.strikinglycdn.com/files/04578560-d149-451d-8b12-7d11f823c804/87042961550.pdf
- https://s3.amazonaws.com/gezejoputiwinu/gegivewosetidapedomixot.pdf
- https://uploads.strikinglycdn.com/files/0d4a4347-f7df-40be-ae49-7293e6338851/22127994462.pdf
- https://uploads.strikinglycdn.com/files/32701434-af0e-4545-9112-b6ef4f4561f8/zamiz.pdf
- https://s3.amazonaws.com/kokesatodixon/cash_flow_to_creditors_debt_holders_is_defined_as.pdf
- https://uploads.strikinglycdn.com/files/da7c27d2-8d74-4e80-862a-26278cb0be5e/lowinuduwi.pdf
- https://s3.amazonaws.com/tabobujimo/ley_organica_de_la_administracion_publica_federal.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report