SUSPICIOUS — 9278426.pdf
SUSPICIOUS — 9278426.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
1007478edaf1f03f73db2f8b70dab25be36ddc8dacedd1f365da279b79864b63 - SHA-1:
47812291a3054d7007c35c6c171d17533c7600c4 - MD5:
379aa0709341d457531b9d64468811e2 - ssdeep:
768:YgGzpDcQORFnPqPTnPwPbnThnPSnP+84WYwVQURL2jVcpbeYozXVtx5gH1V4o8+V:1GFoQOheeYcFO/4oN3Ya02w8mbPXJdE - TLSH:
T15F319DF39097DE8D7AC79B036EEA24595188C68C6032E760089C7B6CD4BC6EC7F505A1 - Submitted as: 9278426.pdf
- File type: pdf · Size: 42605 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=group%207%20periodic%20table%20elements, https://cdn.shopify.com/s/files/1/0501/8786/2194/files/putlocker_charlie_s_angels.pdf, https://cdn.shopify.com/s/files/1/0492/2871/0041/files/transformers_prime_breakdown_death.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=group%207%20periodic%20table%20elements
- https://cdn.shopify.com/s/files/1/0497/1970/5761/files/3635481942.pdf
- https://cdn.shopify.com/s/files/1/0501/8786/2194/files/putlocker_charlie_s_angels.pdf
- https://cdn.shopify.com/s/files/1/0492/2871/0041/files/transformers_prime_breakdown_death.pdf
- https://cdn-cms.f-static.net/uploads/4401525/normal_5f954525506fb.pdf
- https://s3.amazonaws.com/xezujuxoz/slope_game_unblocked_76.pdf
- https://s3.amazonaws.com/pisedij/danielle_steel.pdf
- https://cdn-cms.f-static.net/uploads/4367296/normal_5f87e72c5fbd6.pdf
- https://cdn-cms.f-static.net/uploads/4374857/normal_5f8a95b03da87.pdf
- https://cdn.shopify.com/s/files/1/0438/3644/0733/files/directv_sports_vr_app_apk.pdf
- https://cdn-cms.f-static.net/uploads/4369771/normal_5f88503c747ef.pdf
- https://cdn.shopify.com/s/files/1/0429/5104/9370/files/download_driver_toolkit_crack_setup_2019.pdf
- https://cdn.shopify.com/s/files/1/0483/7277/7109/files/45556828286.pdf
- https://cdn-cms.f-static.net/uploads/4403804/normal_5f9242f76d9bd.pdf
- https://cdn.shopify.com/s/files/1/0266/8970/0027/files/best_android_games_without_ads.pdf
- https://s3.amazonaws.com/zikeko/davulumidoletuwawusipe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report