SUSPICIOUS — bfcc299c35.pdf
SUSPICIOUS — bfcc299c35.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
265b8ed126d9e0d1a764000bb75972dd3a6bf54e2543d45419df2f0f82517f40 - SHA-1:
bcc71254c6a2cd906bedbb648ec896948d8dfde0 - MD5:
d931684485fc6f0ab3b6df4dcf27c6ed - ssdeep:
768:5gGzpDdcFIlqbodkuMv5NW7vdVzq5ymfU4IXjhSk0TK1gSYs3PDez+dTwZJKEOOT:6GFRcl9BNWZY5TfYX50TKVYs3qyEKEOG - TLSH:
T18B328DF75087EC9D79869B43AAAB146DA08BD30D2036D72044CC772ED5BC6AE3E10C65 - Submitted as: bfcc299c35.pdf
- File type: pdf · Size: 47547 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=cross%20price%20elasticity%20of%20demand%20examples%20pdf, https://uploads.strikinglycdn.com/files/75770efe-1894-4e3d-8819-9dc1084242cb/8448295986.pdf, https://bakukumi.weebly.com/uploads/1/3/4/4/134437371/5a676ee3bf08e0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=cross%20price%20elasticity%20of%20demand%20examples%20pdf
- https://uploads.strikinglycdn.com/files/75770efe-1894-4e3d-8819-9dc1084242cb/8448295986.pdf
- https://bakukumi.weebly.com/uploads/1/3/4/4/134437371/5a676ee3bf08e0.pdf
- https://fukoxifixe.weebly.com/uploads/1/3/4/4/134460993/9736512.pdf
- https://uploads.strikinglycdn.com/files/2dccaa3f-6144-45d1-9781-fb65b3dd63e6/11660687978.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/mixabokika-xanadujane.pdf
- https://uploads.strikinglycdn.com/files/dcd8c654-9457-4646-b436-36bc54ca2c6f/gafinumopobexilojumamil.pdf
- https://zadavutuni.weebly.com/uploads/1/3/4/3/134343582/dalutajoze.pdf
- https://uploads.strikinglycdn.com/files/219803da-1e5e-44bb-8d16-1923fc1dea30/donuneliroduloxaxipaxe.pdf
- https://uploads.strikinglycdn.com/files/44ef295f-0d53-404b-8d8d-309328cc2b44/33606589506.pdf
- https://cdn.shopify.com/s/files/1/0428/9737/5388/files/salamat_full_song_wapking.pdf
- https://cdn.shopify.com/s/files/1/0266/8501/4213/files/the_censors_book.pdf
- https://cdn.shopify.com/s/files/1/0484/1701/3912/files/85759765796.pdf
- https://uploads.strikinglycdn.com/files/aa652014-bfa3-4c6e-8339-04fcecc57e90/43820752212.pdf
- https://zewonawexekuke.weebly.com/uploads/1/3/4/3/134318694/sapob-welepuxelexu-wesumufore-guvim.pdf
- https://naxedomabaxa.weebly.com/uploads/1/3/1/6/131606472/noxezulozegu.pdf
- https://uploads.strikinglycdn.com/files/b88c5ebf-d332-433e-a5e1-940810aa9592/zotomarazag.pdf
- https://xalipifizipig.weebly.com/uploads/1/3/1/3/131379045/migekamubomod_mafanijexenes.pdf
- https://cdn.shopify.com/s/files/1/0483/7031/9509/files/evolution_review_worksheet.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/jibepare-vudaramuzi-refirezagulele.pdf
- https://uploads.strikinglycdn.com/files/2f2f0093-49e4-4e9d-bfdb-e55435c185e8/marvel_heroic_roleplaying.pdf
- https://cdn.shopify.com/s/files/1/0435/0204/3288/files/mahindra_3016_owners_manual.pdf
- https://gepobuxew.weebly.com/uploads/1/3/1/0/131070920/wiridig-jofolunolizodi-judaxuwanizitup-gevufo.pdf
- https://bajusumuke.weebly.com/uploads/1/3/2/7/132741128/xitimuzelowolege.pdf
- https://uploads.strikinglycdn.com/files/2e826a3f-837b-4bb5-aadd-dbf2dd00a610/xinokower.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- bakukumi.weebly.com
- fukoxifixe.weebly.com
- dejolezeg.weebly.com
- zadavutuni.weebly.com
- cdn.shopify.com
- zewonawexekuke.weebly.com
- naxedomabaxa.weebly.com
- xalipifizipig.weebly.com
- mogilifus.weebly.com
- gepobuxew.weebly.com
- bajusumuke.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report