SUSPICIOUS — 9712797.pdf
SUSPICIOUS — 9712797.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
1ab95a2ff11a0d4eeb255d7c4115c2cdbd95acb484b1a184df381755a8ed59b5 - SHA-1:
601d4d148efdf454ce2003579d5b8e15d16d32e0 - MD5:
842f851bb733a13f0164d47320580564 - ssdeep:
768:NgGzpDJpkiabcVCLGGWilX25bgIDZm6TnarMX6wr02S7r0tkBBYX6:uGFlpkMZr4I6QMrAkBBYX6 - TLSH:
T1FD317CF300A3EE8D3983AF536EAE254E6049D7486132E25048983B6CC47C7BDBF10961 - Submitted as: 9712797.pdf
- File type: pdf · Size: 39711 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=fisica%20y%20quimica%201%20bachillerato%20sant, https://cdn.shopify.com/s/files/1/0434/9709/5333/files/gozutemikaj.pdf, https://cdn.shopify.com/s/files/1/0437/2856/8471/files/dell_precision_t5400_motherboard.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=fisica%20y%20quimica%201%20bachillerato%20sant
- https://cdn.shopify.com/s/files/1/0434/9709/5333/files/gozutemikaj.pdf
- https://cdn.shopify.com/s/files/1/0437/2856/8471/files/dell_precision_t5400_motherboard.pdf
- https://cdn.shopify.com/s/files/1/0485/0250/5627/files/28278530243.pdf
- https://cdn.shopify.com/s/files/1/0498/4517/4439/files/sisejasizexeka.pdf
- https://cdn.shopify.com/s/files/1/0472/2920/6693/files/fejikivijifebebeve.pdf
- https://cdn.shopify.com/s/files/1/0428/8934/7228/files/texas_instruments_ti-34_ii_logarithmus.pdf
- https://cdn.shopify.com/s/files/1/0431/2639/0946/files/18247742871.pdf
- https://cdn.shopify.com/s/files/1/0481/6443/8173/files/ninja_4-quart_air_fryer.pdf
- https://cdn.shopify.com/s/files/1/0439/1128/2843/files/acer_predator_g3-710_case.pdf
- https://cdn.shopify.com/s/files/1/0433/6828/4319/files/48735171405.pdf
- https://uploads.strikinglycdn.com/files/23c46434-3f25-417a-af72-2ea60f217b7a/fibumavozipuditunelasig.pdf
- https://uploads.strikinglycdn.com/files/fe3f3b52-7043-4e0f-a5f7-052873cd41a6/75414002549.pdf
- https://cdn.shopify.com/s/files/1/0433/1261/1481/files/contempronous_effect_lagged_effects.pdf
- https://cdn.shopify.com/s/files/1/0431/3569/7063/files/46714668771.pdf
- https://cdn.shopify.com/s/files/1/0485/0987/8427/files/81004917135.pdf
- https://site-1038367.mozfiles.com/files/1038367/15429808436.pdf
- https://site-1038303.mozfiles.com/files/1038303/zederawuwijis.pdf
- https://site-1036761.mozfiles.com/files/1036761/53364385851.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1038367.mozfiles.com
- site-1038303.mozfiles.com
- site-1036761.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report