SUSPICIOUS — 9660614.pdf
SUSPICIOUS — 9660614.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
16f5b79c88b98ef2d014f38dde123393f619857f8976bc91a5cec65c1c510179 - SHA-1:
f6f1ca366b16964b44d72506a355f5e1159d0bba - MD5:
fb823ef5ec0ebff35edd7cf3e1884dd6 - ssdeep:
768:mgGzpD2pPifSYrk/Zwd5OYsLtCUpIc74cRSqyVuMYWPcSZbPgF:zGFipPKHUuojIqI9DPbZbPgF - TLSH:
T11E338DF36497ED8C7ACA9F03ADAA049A5189C3886137E390458C776DE4BC6BD3E10950 - Submitted as: 9660614.pdf
- File type: pdf · Size: 48149 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=treaty%20of%20fort%20jackson, https://cdn.shopify.com/s/files/1/0434/7016/0032/files/joranenajepub.pdf, https://cdn.shopify.com/s/files/1/0488/9847/4143/files/43627949921.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=treaty%20of%20fort%20jackson
- https://cdn.shopify.com/s/files/1/0496/3916/2005/files/68999521325.pdf
- https://cdn.shopify.com/s/files/1/0434/7016/0032/files/joranenajepub.pdf
- https://cdn.shopify.com/s/files/1/0488/9847/4143/files/43627949921.pdf
- https://cdn.shopify.com/s/files/1/0485/9920/4000/files/68513345056.pdf
- https://s3.amazonaws.com/memul/cengage_mathematics_algebra.pdf
- https://s3.amazonaws.com/susopuzupure/branching_process_in_stochastic.pdf
- https://s3.amazonaws.com/mijedusovineti/bank_exam_today_english_grammar.pdf
- https://s3.amazonaws.com/henghuili-files/gasijoxo.pdf
- https://s3.amazonaws.com/pazifetanegapu/54288813419.pdf
- https://uploads.strikinglycdn.com/files/6879181f-6044-4579-96d0-5e3effa0df02/33988131191.pdf
- https://uploads.strikinglycdn.com/files/42a45620-c8d5-4273-8fab-0be28bc4672d/56528419039.pdf
- https://uploads.strikinglycdn.com/files/c23c2abc-db21-4f59-8c45-d5a301729ed5/nomimibuvowamesupevuxibe.pdf
- https://uploads.strikinglycdn.com/files/4274290b-5f25-40d8-8084-2c7580d99938/85685560704.pdf
- https://uploads.strikinglycdn.com/files/b80f5d48-b35a-4247-af8c-72f1711999e3/72404199115.pdf
- https://uploads.strikinglycdn.com/files/31a5a497-480e-458b-a56f-efe65f1b18b5/85744056862.pdf
- https://uploads.strikinglycdn.com/files/c51009b7-0506-4620-af9b-1b71d06407f5/1972918351.pdf
- https://uploads.strikinglycdn.com/files/a09b7cdb-d234-466e-b34f-3686ae5f3df0/lugigirarorakupipepunife.pdf
- https://uploads.strikinglycdn.com/files/113c66fc-178f-4b7e-b9ab-5b78e547df41/divorisafa.pdf
- https://xujaxivef.weebly.com/uploads/1/3/1/4/131438557/faxifulusu.pdf
- https://texitanoz.weebly.com/uploads/1/3/0/7/130739996/sutonolob-taniwov.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/falepibeboxek.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/lezepasidixabazafe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- xujaxivef.weebly.com
- texitanoz.weebly.com
- tipefejiri.weebly.com
- megadezatesaram.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report