SUSPICIOUS — 9273865.pdf
SUSPICIOUS — 9273865.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
28abcc4ff8293b8d10cd20e3868e54a465e6f8635b3165f2de88dc90d66591ec - SHA-1:
dec7bd1aaff5d66b0fc72137e1d166b5a3ec1345 - MD5:
3b90ab405ba611205bafe339dd109211 - ssdeep:
768:JgGzpDvCc4EFJpzEDAbZLLj+WJEuL2T6D1oxbKYIl01Pt1I:qGFjCc/RiGohpE8PI - TLSH:
T1F832AFF365BBEDCC7B866F1368E614946149D6883133E96098D8776CC0BC1BEAE41831 - Submitted as: 9273865.pdf
- File type: pdf · Size: 45761 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=google%20drive%20shrek%204, https://cdn-cms.f-static.net/uploads/4372723/normal_5f8c4aba9941e.pdf, https://uploads.strikinglycdn.com/files/10e5d05c-08a0-447c-8d3a-0bd71b5496b7/duvozavabudowosawasozile.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=google%20drive%20shrek%204
- https://s3.amazonaws.com/zupenafud/37926536101.pdf
- https://cdn-cms.f-static.net/uploads/4372723/normal_5f8c4aba9941e.pdf
- https://uploads.strikinglycdn.com/files/10e5d05c-08a0-447c-8d3a-0bd71b5496b7/duvozavabudowosawasozile.pdf
- https://cdn-cms.f-static.net/uploads/4377102/normal_5f8a5f55b0920.pdf
- https://s3.amazonaws.com/fedufiporara/prepositions_exercises_with_pictures.pdf
- https://cdn-cms.f-static.net/uploads/4381544/normal_5f91d64a701e6.pdf
- https://uploads.strikinglycdn.com/files/8c3e4cc5-83c2-445c-9f03-69daad0733a7/oru_murai_vanthu_parthaya_mp3_download.pdf
- https://s3.amazonaws.com/jotizifime/un_beso_y_una_flor_cover.pdf
- https://s3.amazonaws.com/newopetusam/activity_1.1.3_gears_answer_key.pdf
- https://cdn-cms.f-static.net/uploads/4374371/normal_5f8b3335e9a9e.pdf
- https://uploads.strikinglycdn.com/files/9e3fe1b7-73a7-46d0-a977-6171f6db9d3f/que_es_la_contraargumentacin.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report