SUSPICIOUS — 6763278.pdf
SUSPICIOUS — 6763278.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
19cac65d09a338a48292e24b47224524441b27d75a475affc397c8b030ee99a0 - SHA-1:
d08827d9750823e9cd2a707e9dc588571c7d7450 - MD5:
eff26f836ac5161fbb95f6fb12fa16a6 - ssdeep:
768:egGzpDvpqee2PWiySgIZ9kJkgTNGltdfWi85qhoWIv06MfN:bGFrpq7fm9gkCo5eD5Os0vfN - TLSH:
T184318EF35093EC8C7E8E6F07AEA711896149E78D9032D661458C762DC47CAFD6E00E62 - Submitted as: 6763278.pdf
- File type: pdf · Size: 42968 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=lanitas%20examenes%20de%20primaria, https://uploads.strikinglycdn.com/files/dac244ac-19c4-4214-bfb7-ca056f710e2f/milom.pdf, https://uploads.strikinglycdn.com/files/87a81d58-2dea-4ca4-97ca-a75f305ba3d0/wisanodesivowiriwakin.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=lanitas%20examenes%20de%20primaria
- https://uploads.strikinglycdn.com/files/dac244ac-19c4-4214-bfb7-ca056f710e2f/milom.pdf
- https://uploads.strikinglycdn.com/files/87a81d58-2dea-4ca4-97ca-a75f305ba3d0/wisanodesivowiriwakin.pdf
- https://uploads.strikinglycdn.com/files/e4b7f455-a067-4be5-a453-1501a930a9eb/fawaxetosamujoti.pdf
- https://uploads.strikinglycdn.com/files/822437e0-93ff-424f-89f3-d44f32537c1c/vedamelawe.pdf
- https://uploads.strikinglycdn.com/files/cab6a2b6-b10d-4611-9718-0e17e881a30d/53136382094.pdf
- https://uploads.strikinglycdn.com/files/2bf33b85-d543-49ba-a048-29b74da5cb3b/jadenenofiralutifimeliza.pdf
- https://uploads.strikinglycdn.com/files/1744a567-17ea-43ac-9a2d-df7ef2299cc8/eldritch_blast_dnd_5e.pdf
- https://cdn.shopify.com/s/files/1/0434/2687/3509/files/los_angeles_sanitation_department_bulky_item_pickup.pdf
- https://cdn.shopify.com/s/files/1/0495/5327/7088/files/at_home_austin.pdf
- https://cdn.shopify.com/s/files/1/0498/7427/2408/files/preguntas_capciosas_de_matematicas.pdf
- https://uploads.strikinglycdn.com/files/a1991d02-ce30-49e5-8807-d1ffa3d7fca3/64036381910.pdf
- https://uploads.strikinglycdn.com/files/15e42b50-501e-4fc4-845e-1011ba8c3dcd/22541112544.pdf
- https://uploads.strikinglycdn.com/files/e6005260-e9af-45c6-8cf9-dc63f3fa39cb/xukesozosu.pdf
- https://cdn.shopify.com/s/files/1/0440/2806/8005/files/67173977551.pdf
- https://cdn.shopify.com/s/files/1/0484/8815/3250/files/lean_in_graduates.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/3718456.pdf
- https://finazodaxuvoj.weebly.com/uploads/1/3/2/6/132682535/zudovokuxarataw_gepujanomoni.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1377318.pdf
- https://talapilodegopez.weebly.com/uploads/1/3/0/9/130969507/a28e7d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- jakedekokobara.weebly.com
- finazodaxuvoj.weebly.com
- dutitujazekap.weebly.com
- talapilodegopez.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report