SUSPICIOUS — 5756966.pdf
SUSPICIOUS — 5756966.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
20d52f8cb92a983b42b80ca5d490bdf5928865ba909db0e89f36d734a4a0510f - SHA-1:
8a635145c2ce21e97263c398c4ebb8fca6089873 - MD5:
77c7c006e2b19343f001dadcf0f11c80 - ssdeep:
1536:mGFHee6mw03V8s7uuyMlD3WKf1QTMWI+lw2bvc6Ax:/FHef0Gs+EJ9QT8+lFvcD - TLSH:
T18434AEF3409BDD8C7A87A743ADEA2459914AC74D7133EB9405887B6EC0BCA7CAE10911 - Submitted as: 5756966.pdf
- File type: pdf · Size: 57008 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=watch%20a%20star%20is%20born%20putlocker, https://cdn-cms.f-static.net/uploads/4365652/normal_5f8759ef93518.pdf, https://cdn-cms.f-static.net/uploads/4366377/normal_5f87c281b1bc8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=watch%20a%20star%20is%20born%20putlocker
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8759ef93518.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f87c281b1bc8.pdf
- https://cdn-cms.f-static.net/uploads/4366993/normal_5f87ebc53213e.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f874f32bd08d.pdf
- https://cdn-cms.f-static.net/uploads/4366312/normal_5f87565b4d60c.pdf
- https://site-1040299.mozfiles.com/files/1040299/natural_science_grade_7_worksheets_caps.pdf
- https://site-1041682.mozfiles.com/files/1041682/makunetimijibamojovuximuv.pdf
- https://uploads.strikinglycdn.com/files/e349ba90-aefe-4c8d-94f4-6ff8ebb05b28/vesuzeju.pdf
- https://uploads.strikinglycdn.com/files/d3f5828a-3cbb-4810-820c-457e6041f1f8/71096686253.pdf
- https://uploads.strikinglycdn.com/files/a169e275-c8fa-4549-980f-e8c6753ee8c9/78179722333.pdf
- https://uploads.strikinglycdn.com/files/c12507ed-d319-4257-bbe4-574cae975df7/24440919024.pdf
- https://uploads.strikinglycdn.com/files/8fc66f43-413b-40d3-af80-aeb06ddcaa67/51412672485.pdf
- https://uploads.strikinglycdn.com/files/e9da89a8-9a4c-4bf7-b178-5b91cd43fe67/sovopulixo.pdf
- https://uploads.strikinglycdn.com/files/ad843440-22c2-43a5-a330-593ad3a2e68b/xedel.pdf
- https://cdn.shopify.com/s/files/1/0436/2056/5156/files/colder_than_you_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0431/4506/8699/files/39984297902.pdf
- https://uploads.strikinglycdn.com/files/517d4672-f912-4b54-a0cf-62f026bbbbde/ruvafigedadoxu.pdf
- https://uploads.strikinglycdn.com/files/33489973-5e1d-4d87-9e20-fff94f5f3a84/58713217586.pdf
- https://uploads.strikinglycdn.com/files/e28666dc-c9d8-4700-bdb0-b341d4194394/91522901017.pdf
- https://uploads.strikinglycdn.com/files/5d8773cc-e2b4-4b09-9a84-efb2360a8ee3/liteboleg.pdf
- https://uploads.strikinglycdn.com/files/06e374f1-58a2-48e3-b024-14bf9cb00117/xepizoki.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1040299.mozfiles.com
- site-1041682.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report