SUSPICIOUS — 2cc3c056dd7b9f3.pdf
SUSPICIOUS — 2cc3c056dd7b9f3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2182859a191e8247a86d51c28eab7939c560fd58e14e84115744a6e26515da9a - SHA-1:
193e0786b67857076ff093a8b6db9ec60ff92843 - MD5:
2f8ff253454f958bc1a63d919ca7594a - ssdeep:
1536:4GFEp10s0+soC0W5K6/+YXwoZ3mNXRKjc3S76aiCE6:VFEpe/oAXwSmNBESS76pc - TLSH:
T19B35AEF30097ED8C7B8A5F23A9B711596189D38DA137AB5044DC372DD4BC69E6F00A22 - Submitted as: 2cc3c056dd7b9f3.pdf
- File type: pdf · Size: 60320 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=dragon%20ball%20xenoverse%202%20all%20trainers, https://uploads.strikinglycdn.com/files/ec688157-6e1c-48bf-9479-cdfefd33f308/29654236233.pdf, https://uploads.strikinglycdn.com/files/29969c86-76ef-4c36-97cb-e97cad00514e/72803483827.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=dragon%20ball%20xenoverse%202%20all%20trainers
- https://uploads.strikinglycdn.com/files/ec688157-6e1c-48bf-9479-cdfefd33f308/29654236233.pdf
- https://uploads.strikinglycdn.com/files/29969c86-76ef-4c36-97cb-e97cad00514e/72803483827.pdf
- https://uploads.strikinglycdn.com/files/723d8ff6-7236-40bb-b557-25a47490d98b/27462305237.pdf
- https://uploads.strikinglycdn.com/files/65594d11-5ef3-4ee0-83f7-4fa02ee33929/zupusekizejoniriwofakodo.pdf
- https://uploads.strikinglycdn.com/files/e8f97db4-5680-41a1-ab4a-b2024ab00461/kamemefizixavaratowekad.pdf
- https://uploads.strikinglycdn.com/files/5c03ba1a-f374-42b3-9363-6fb3cd2e151d/tekesarumodumitu.pdf
- https://uploads.strikinglycdn.com/files/e6ea6fd0-edc7-47de-b001-1b3f5726d6e7/98095077213.pdf
- https://uploads.strikinglycdn.com/files/4563e6b3-5223-4b59-9627-ca055e1189d7/fikajuzipimobux.pdf
- https://uploads.strikinglycdn.com/files/d8322124-7103-4bfa-b9ac-9b0490ba80fe/mixozufepevusapas.pdf
- https://uploads.strikinglycdn.com/files/8fb18da8-427f-40c1-8e3f-9eb94b47fc0c/28678032512.pdf
- https://zulatikuwa.weebly.com/uploads/1/3/0/7/130776211/2745832.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/bifulep-giwoxa.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/lukuxaluk.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/9b53ec72f.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf
- https://cdn.shopify.com/s/files/1/0476/7727/6326/files/pokemon_emerald_cute_contest_moves.pdf
- https://cdn.shopify.com/s/files/1/0436/3649/0398/files/20619682228.pdf
- https://cdn.shopify.com/s/files/1/0495/7467/4584/files/citra_mii_maker_download.pdf
- https://cdn.shopify.com/s/files/1/0478/6651/1526/files/incredible_5_point_scale_printable_template.pdf
- https://site-1043406.mozfiles.com/files/1043406/jolavanenimozedereb.pdf
- https://site-1037909.mozfiles.com/files/1037909/17824660409.pdf
- https://site-1038391.mozfiles.com/files/1038391/tabasovuwotonabazebevojuz.pdf
- https://site-1039266.mozfiles.com/files/1039266/69602045578.pdf
- https://cdn-cms.f-static.net/uploads/4366646/normal_5f8784b39a65e.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- zulatikuwa.weebly.com
- zesopupejilit.weebly.com
- bedizegoresupa.weebly.com
- mogilifus.weebly.com
- narogigadi.weebly.com
- cdn.shopify.com
- site-1043406.mozfiles.com
- site-1037909.mozfiles.com
- site-1038391.mozfiles.com
- site-1039266.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report