SUSPICIOUS — c36df7ab1db.pdf
SUSPICIOUS — c36df7ab1db.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2d2eb5c2d9d7b131d879be1021155364463d9ee379263208abf837409560686d - SHA-1:
5e1d46df5c4e941da6f01e4e635de6e76f6a94ee - MD5:
7ca08194154b9c2960d8235612b9d6a9 - ssdeep:
1536:EGFOpBKMGUPp+GKZ6Zz0JSa0WcjUvKdE/ao:RFOpBTIo5aSaQkV - TLSH:
T19934BFF350E7ED8CBE86AB43A9E61555208EC7896237A79048CC7A3DC0BC6BD6D00D51 - Submitted as: c36df7ab1db.pdf
- File type: pdf · Size: 53421 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=keepers%20of%20the%20light%20oracle, https://uploads.strikinglycdn.com/files/6896b126-31bd-4f00-9c4d-ec668533830b/lesowaj.pdf, https://uploads.strikinglycdn.com/files/96a725b8-7dd4-41a6-86ab-caeed1fe1374/vezipizanazizubexe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=keepers%20of%20the%20light%20oracle
- https://uploads.strikinglycdn.com/files/6896b126-31bd-4f00-9c4d-ec668533830b/lesowaj.pdf
- https://uploads.strikinglycdn.com/files/96a725b8-7dd4-41a6-86ab-caeed1fe1374/vezipizanazizubexe.pdf
- https://uploads.strikinglycdn.com/files/6b71c826-2683-435f-ba9e-39b1918be62e/48465498810.pdf
- https://uploads.strikinglycdn.com/files/3a06e24a-987f-46ee-acae-bf38da5f3453/tezejopon.pdf
- https://uploads.strikinglycdn.com/files/9b8739ba-dee5-4da8-83a3-a5faca397b24/likakesige.pdf
- https://uploads.strikinglycdn.com/files/4799ee6a-cb34-447a-ad33-98aa9128959e/pukizebepegovob.pdf
- https://uploads.strikinglycdn.com/files/2df60d84-af0f-442e-8654-fe22bc5e2c95/zifolejepirafadogogodajud.pdf
- https://cdn-cms.f-static.net/uploads/4368741/normal_5f878c5042ce7.pdf
- https://cdn-cms.f-static.net/uploads/4368996/normal_5f878eeddff77.pdf
- https://site-1039311.mozfiles.com/files/1039311/43305139727.pdf
- https://site-1041594.mozfiles.com/files/1041594/29397526184.pdf
- https://site-1043471.mozfiles.com/files/1043471/tidefotipaxuvoloritupiw.pdf
- https://site-1039261.mozfiles.com/files/1039261/85003532710.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf
- https://rigonabex.weebly.com/uploads/1/3/1/4/131483185/223756.pdf
- https://uploads.strikinglycdn.com/files/644e507e-e659-44ff-9ace-84c81d170c87/vutenefurodunubunavek.pdf
- https://uploads.strikinglycdn.com/files/aa8db0d0-d92a-45ae-bace-6e5dae662823/sabatimulozivaw.pdf
- https://uploads.strikinglycdn.com/files/b2fbd06e-2126-43b1-b197-3e38683f6094/73161006884.pdf
- https://uploads.strikinglycdn.com/files/83158a83-7e73-4bce-ac9b-b27f6f016755/34724279472.pdf
- https://uploads.strikinglycdn.com/files/61b78b8b-6814-44ca-a867-d68b7421e2d1/bamil.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1039311.mozfiles.com
- site-1041594.mozfiles.com
- site-1043471.mozfiles.com
- site-1039261.mozfiles.com
- jakedekokobara.weebly.com
- rigonabex.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report