SUSPICIOUS — 54579.pdf
SUSPICIOUS — 54579.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
1f2f58a49eab066acc121bcb374876a7cb2448eb0f858f04fb4422fcd3683bbc - SHA-1:
81b6f5882e848d6373f859fd15a51aeeb5e379e4 - MD5:
dc60b028680a263e2592bfc5ae34af5d - ssdeep:
768:WbgGzpDi88Gf2MdI2MNDNVkfXqpW7DGEALZINCX+Fcq6uhUXbMXPW/dH+G8zC:5GFnXqpW7DbGINC+FcqZibSPW/w/zC - TLSH:
T1E1338DF30097DD8DBB8BAF43B9A704A9A18AC78861329790499CB73CD47C5BD6F11850 - Submitted as: 54579.pdf
- File type: pdf · Size: 49222 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=1-%D8%B9%D8%A7%D8%AF%D9%84%20%D9%82%D8%B1%D9%8A%D8%B4%D9%8A%20%D9%86%D8%A7%D8%AA%20%D8%AE%D9%88%D8%A7%D9%86, https://cdn.shopify.com/s/files/1/0494/7070/1735/files/hylatopic_plus_cream.pdf, https://cdn.shopify.com/s/files/1/0433/0147/0366/files/99319295040.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=1-%D8%B9%D8%A7%D8%AF%D9%84%20%D9%82%D8%B1%D9%8A%D8%B4%D9%8A%20%D9%86%D8%A7%D8%AA%20%D8%AE%D9%88%D8%A7%D9%86
- https://cdn.shopify.com/s/files/1/0494/7070/1735/files/hylatopic_plus_cream.pdf
- https://cdn.shopify.com/s/files/1/0433/0147/0366/files/99319295040.pdf
- https://cdn.shopify.com/s/files/1/0462/2372/0602/files/honeymoon_lana_del_rey_zip.pdf
- https://cdn.shopify.com/s/files/1/0501/0246/8765/files/medical_leave_application_letter.pdf
- https://cdn.shopify.com/s/files/1/0429/5308/0991/files/nulosusute.pdf
- https://uploads.strikinglycdn.com/files/f542deea-3557-468e-a758-5be685e20243/32585534096.pdf
- https://uploads.strikinglycdn.com/files/b1837e29-3cc3-4956-83f3-2e5431c7e6d6/wisurup.pdf
- https://uploads.strikinglycdn.com/files/647cd612-25ab-4274-bea6-efe07de62d11/69438575184.pdf
- https://uploads.strikinglycdn.com/files/1fe55b9c-7901-415e-95d7-f79142a886dc/55407679782.pdf
- https://cdn-cms.f-static.net/uploads/4369138/normal_5f88aca48359e.pdf
- https://cdn-cms.f-static.net/uploads/4368953/normal_5f8995e0e33a6.pdf
- https://cdn-cms.f-static.net/uploads/4368265/normal_5f87721d5c517.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f897421ce3ca.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f87be31b9f67.pdf
- https://uploads.strikinglycdn.com/files/f1c22b9c-e024-4392-8aa3-795040c5fc8d/79105051126.pdf
- https://uploads.strikinglycdn.com/files/85f6f38e-1c15-415b-81ba-513b7c2a58f8/49854871756.pdf
- https://uploads.strikinglycdn.com/files/d9f66212-9dc4-49da-9b68-7ebc28a15bcf/94011861478.pdf
- https://uploads.strikinglycdn.com/files/441b6fa9-d32b-403b-9368-2480e732a452/dugedavufus.pdf
- https://uploads.strikinglycdn.com/files/877115f2-7d02-4395-81ce-3b123613dfb3/fasukugojufijizebasofumi.pdf
- https://pejapuvurexoku.weebly.com/uploads/1/3/1/6/131636728/linotetemarofifeg.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/2613559.pdf
- https://debasomi.weebly.com/uploads/1/3/0/7/130739769/18b3dc9062.pdf
- https://buluzuzumaz.weebly.com/uploads/1/3/1/6/131636727/xibebaje-morebadekedazu-vofubotegisi-notune.pdf
- https://givexikiduxa.weebly.com/uploads/1/3/1/3/131398224/4127a67afe.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- pejapuvurexoku.weebly.com
- medizagokitoni.weebly.com
- debasomi.weebly.com
- buluzuzumaz.weebly.com
- givexikiduxa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report