SUSPICIOUS — 7f8acae73467b2.pdf
SUSPICIOUS — 7f8acae73467b2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
fc2bf550732f534227dda220c685954ca9a4ae1f227cc9cb8be10e04b4393d11 - SHA-1:
e40eafd19b2d0a28bc733fcb4d9b6655072d3c8b - MD5:
38535a050012aa5d56e00fd6c201ceb5 - ssdeep:
768:JgGzpDTiXy5lDdEF+TMfYLNNBbdKBd6NC6SXVloeAZM8n+ED:qGF/mUkF+T72OQrXnAZM8n+ED - TLSH:
T14D328DF354A7EC4C7A8BAB036DBA119D6189C7486036976084DC772DC0BC6BD6F11E60 - Submitted as: 7f8acae73467b2.pdf
- File type: pdf · Size: 43806 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=pdf%20rasterize%20all%20text, https://uploads.strikinglycdn.com/files/591fbdcd-dab1-4693-939c-6c7954d87032/comfort_glow_kerosene_heater_manual.pdf, https://uploads.strikinglycdn.com/files/c1ea0019-9e27-41f4-9caf-89963efc092b/xodemevemepexebebufobipop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=pdf%20rasterize%20all%20text
- https://uploads.strikinglycdn.com/files/591fbdcd-dab1-4693-939c-6c7954d87032/comfort_glow_kerosene_heater_manual.pdf
- https://uploads.strikinglycdn.com/files/c1ea0019-9e27-41f4-9caf-89963efc092b/xodemevemepexebebufobipop.pdf
- https://uploads.strikinglycdn.com/files/569bfca7-96a0-479a-8c53-72c29e49db20/12341707205.pdf
- https://uploads.strikinglycdn.com/files/d459a688-54a9-4e06-a2a7-dce41bf94ba2/36370959947.pdf
- https://uploads.strikinglycdn.com/files/0db1b603-94f4-4b92-b866-1a26bc151bec/the_red_tent_movie_free.pdf
- https://uploads.strikinglycdn.com/files/c187e2b4-e2d4-47ee-9c7f-c975826c476b/dobevis.pdf
- https://uploads.strikinglycdn.com/files/792ea4e1-baed-46a8-9f2e-6d010e0c0824/tatuvutuvajip.pdf
- https://uploads.strikinglycdn.com/files/ed3a395b-fe5d-443c-9818-8e4dd90ced0c/80186883358.pdf
- https://uploads.strikinglycdn.com/files/e47032de-c02e-40e8-8bea-4a8d8537d3d9/62770844978.pdf
- https://cdn-cms.f-static.net/uploads/4371786/normal_5f8e194d9a4da.pdf
- https://cdn-cms.f-static.net/uploads/4386622/normal_5f8d6da44bfcf.pdf
- https://uploads.strikinglycdn.com/files/375407e4-ccfa-4d47-a7af-fb9651f1a7f7/fiderutuxokiviv.pdf
- https://uploads.strikinglycdn.com/files/ee2a70ff-862b-441c-9ac7-9f8da12dc80a/xebenedajibupanosef.pdf
- https://uploads.strikinglycdn.com/files/e1e24908-b0c4-4324-95c9-42c4f8ae41a1/12923708141.pdf
- https://siregudak.weebly.com/uploads/1/3/0/7/130738759/9591611.pdf
- https://tibiwurab.weebly.com/uploads/1/3/2/6/132695994/b333adcd30d4d3.pdf
- https://s3.amazonaws.com/levovod/dukakitajiguxutelanasuput.pdf
- https://s3.amazonaws.com/mukutud/asc_us_e_asc_h.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- siregudak.weebly.com
- tibiwurab.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report