SUSPICIOUS — 4245519.pdf
SUSPICIOUS — 4245519.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
24249885a0022eb565b5dfdb7a2761d0829206cd7c5789077b78ab87361cd74c - SHA-1:
301ff3e7bdb88a3608c468f4cd6cb645b360ed6b - MD5:
56670ceea5021b6e6d23284245e8f631 - ssdeep:
768:CgGzpDqpk35EhgW+vATfWnSnZnStEFpe00OXj1hxDm7oNmQRUJC2ukqzVH1w5:fGFmpk3OirtEFptzdDmcYOX2ukqzBS5 - TLSH:
T1E633BFF32197EC8CBA8B6F436EA311896489D38C61269790458C772CC5BC7BD3E146B1 - Submitted as: 4245519.pdf
- File type: pdf · Size: 49403 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=sex%20and%20the%20city%20promo, https://site-1039954.mozfiles.com/files/1039954/warrior_diet_in_tamil.pdf, https://site-1043582.mozfiles.com/files/1043582/manowuropagolenurafasatev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=sex%20and%20the%20city%20promo
- https://site-1039954.mozfiles.com/files/1039954/warrior_diet_in_tamil.pdf
- https://site-1043582.mozfiles.com/files/1043582/manowuropagolenurafasatev.pdf
- https://site-1039911.mozfiles.com/files/1039911/90139382569.pdf
- https://site-1036719.mozfiles.com/files/1036719/siperabogewimaviposumeki.pdf
- https://cdn-cms.f-static.net/uploads/4368759/normal_5f8875c52d27b.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f870002e9154.pdf
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f884d3084da8.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f873026913e7.pdf
- https://cdn.shopify.com/s/files/1/0437/0153/4873/files/rodney_howard_browne_free.pdf
- https://cdn.shopify.com/s/files/1/0435/2573/4552/files/16237332094.pdf
- https://cdn.shopify.com/s/files/1/0432/3357/5075/files/41155053005.pdf
- https://uploads.strikinglycdn.com/files/1081f52b-4f14-4b93-932a-491a229d6933/53794664263.pdf
- https://uploads.strikinglycdn.com/files/06f00f42-c050-4d3f-91de-a7d1774459dd/nugadakofenagiwov.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/8742796.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/83905a54a030772.pdf
- https://uploads.strikinglycdn.com/files/ae7258af-0694-4d57-848b-94a5815e2073/devijexam.pdf
- https://uploads.strikinglycdn.com/files/0bee6b61-9c31-470c-9f8f-e6dc53765832/56409300585.pdf
- https://uploads.strikinglycdn.com/files/20c22e2a-b59a-47f2-a9d7-67cb6b2116c6/pisebolop.pdf
- https://uploads.strikinglycdn.com/files/f1cc1e50-e588-40ef-a26a-1d1c79d2b017/38242967166.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- site-1039954.mozfiles.com
- site-1043582.mozfiles.com
- site-1039911.mozfiles.com
- site-1036719.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- mogilifus.weebly.com
- jakedekokobara.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report