SUSPICIOUS — 4995198.pdf
SUSPICIOUS — 4995198.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
29a70384b2c6df67b0ea1867b7d92f3f91da9d87d719142a50c381c4e2a2ac65 - SHA-1:
51b3befbabd6c7da9ad56b77b6386a8834564463 - MD5:
ad12cb51ca9d9d886e357c3d3b15fa36 - ssdeep:
1536:RGFWmS+De9NAvakbLTil2HKqrtXYmAqw5ICWRqRXXI0zyBJEpu:0FWKo6Haw3RXYmfJ+XYNBJp - TLSH:
T17438F1F3582BDD886A894F43E87521A85C89E74CA03AD73055CDBB6CC4B81BD6E41E30 - Submitted as: 4995198.pdf
- File type: pdf · Size: 84243 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=qpdfview%20open%20in%20new%20window, https://uploads.strikinglycdn.com/files/5d43ae1b-c1d1-492e-aa75-913254e64dad/12097051843.pdf, https://jivexine.weebly.com/uploads/1/3/1/3/131380908/3016426.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=qpdfview%20open%20in%20new%20window
- https://uploads.strikinglycdn.com/files/5d43ae1b-c1d1-492e-aa75-913254e64dad/12097051843.pdf
- https://jivexine.weebly.com/uploads/1/3/1/3/131380908/3016426.pdf
- https://uploads.strikinglycdn.com/files/41f5c04f-5d7e-4418-960b-7a2553636be9/6985998629.pdf
- https://cdn-cms.f-static.net/uploads/4380674/normal_5f8b9c0d56a98.pdf
- https://s3.amazonaws.com/susopuzupure/wusugobudo.pdf
- https://cdn-cms.f-static.net/uploads/4368735/normal_5f99c521729ab.pdf
- https://cdn-cms.f-static.net/uploads/4382193/normal_5f92645ea5eec.pdf
- https://s3.amazonaws.com/tesotiwapax/27142621539.pdf
- https://s3.amazonaws.com/wogikokuzotaxa/pisuvimumovowejezesek.pdf
- https://s3.amazonaws.com/sugosubexez/disifaweseberel.pdf
- https://cdn-cms.f-static.net/uploads/4382208/normal_5f8fd187700f1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- jivexine.weebly.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report