SUSPICIOUS — 7228805.pdf
SUSPICIOUS — 7228805.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2bd2cac268bfa1f20e41eea46d8df704a5213b7ec9af85355a4c0c8a9685fceb - SHA-1:
ae8805e11dce7f308be9a3bf16900c5deb7ea2da - MD5:
6dcd692848de8b3c540752a0f48577fa - ssdeep:
768:FgGzpDoeOCHDhIqJj4TUWRS7zgOquxf9WnHVv+kjrE/JwLTyPF02P4BTdlk1y:WGFMeOwsOqMWHVvxZTV2P43lk1y - TLSH:
T18D329EF3509BDD8C3A8A9B0369BB0465A48EC78D6122CBA0459C776DD47C5FDAE11C20 - Submitted as: 7228805.pdf
- File type: pdf · Size: 45659 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=download%20cber%20flix%20tv, https://cdn-cms.f-static.net/uploads/4366388/normal_5f873daf1e178.pdf, https://cdn-cms.f-static.net/uploads/4366017/normal_5f872c3d50742.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=download%20cber%20flix%20tv
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f873daf1e178.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f872c3d50742.pdf
- https://cdn-cms.f-static.net/uploads/4366304/normal_5f873016b7231.pdf
- https://uploads.strikinglycdn.com/files/a71d3092-7eee-4e67-86e0-4efa216a3b7f/74314579144.pdf
- https://uploads.strikinglycdn.com/files/51efc2ea-8ccd-4191-894a-a09d7b35f9b3/48301348861.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f870f1635d67.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f86fc777bac4.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f87196e0cffb.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f870959349de.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f87119602537.pdf
- https://cdn.shopify.com/s/files/1/0492/3886/8124/files/basil_of_baker_street.pdf
- https://cdn.shopify.com/s/files/1/0268/6851/5012/files/71529768938.pdf
- https://cdn.shopify.com/s/files/1/0484/9631/2482/files/lightning_strikes_song_ozzy.pdf
- https://uploads.strikinglycdn.com/files/611fa60f-7bb3-4b9b-8196-f33cf9ef9eec/38713450800.pdf
- https://uploads.strikinglycdn.com/files/b1fbbbeb-5c77-40dc-9ab9-fb53de4f9fcc/mopaxevof.pdf
- https://site-1043664.mozfiles.com/files/1043664/mesenubidelamux.pdf
- https://site-1039666.mozfiles.com/files/1039666/67326749008.pdf
- https://site-1042665.mozfiles.com/files/1042665/pitozotibugumofewinuse.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1043664.mozfiles.com
- site-1039666.mozfiles.com
- site-1042665.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report