SUSPICIOUS — 7639485.pdf
SUSPICIOUS — 7639485.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2d6879c297288b102039c5b9b1c995a6bd3d62b6299d8006c90c9e7276999a61 - SHA-1:
6ae4e7cb61c4219921c40afff9f299caa242a4bc - MD5:
33e0465541f95492df8465dae6c2593b - ssdeep:
1536:RGFip7N0QozCb6iJ+TmGf1ooJBPJcsGc5:0FipeCGiEKGf1oMBPJPh - TLSH:
T13335B0F301D7ED8C7ACEAB03ADEB11995189C3892137E3604498B66DC47C6BEBE11560 - Submitted as: 7639485.pdf
- File type: pdf · Size: 60846 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=top%20mormon%20tabernacle%20choir%20songs, https://site-1038884.mozfiles.com/files/1038884/lemutipewuvopuwusomep.pdf, https://site-1041770.mozfiles.com/files/1041770/60926840464.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=top%20mormon%20tabernacle%20choir%20songs
- https://site-1038884.mozfiles.com/files/1038884/lemutipewuvopuwusomep.pdf
- https://site-1041770.mozfiles.com/files/1041770/60926840464.pdf
- https://site-1040563.mozfiles.com/files/1040563/24025864080.pdf
- https://site-1040200.mozfiles.com/files/1040200/ernst_and_young_2020_tax_guide.pdf
- https://site-1043408.mozfiles.com/files/1043408/niruto.pdf
- https://uploads.strikinglycdn.com/files/7743a339-5615-42f1-961b-0cccdccbb3c2/46030616198.pdf
- https://uploads.strikinglycdn.com/files/0a024978-a061-40a7-9157-3e2ecb29a34d/fupuloro.pdf
- https://uploads.strikinglycdn.com/files/83b876eb-58a7-445e-904a-5c4f5842eb2b/gapejusujogako.pdf
- https://uploads.strikinglycdn.com/files/a3237714-7402-45fc-aa8d-2f2076b86ce4/purulotobojitovewexafifoj.pdf
- https://site-1039215.mozfiles.com/files/1039215/46561252884.pdf
- https://site-1044162.mozfiles.com/files/1044162/kuvawerim.pdf
- https://uploads.strikinglycdn.com/files/ae40c6b2-43f9-4a7d-8068-e2dbcb4d67c2/83089256293.pdf
- https://uploads.strikinglycdn.com/files/92566107-5aaf-4fcb-a59b-83e1d51b0e62/nomebubilugofatevewof.pdf
- https://uploads.strikinglycdn.com/files/4fcf4446-d64a-45b5-8c3a-5c750291c6c2/74060156170.pdf
- https://uploads.strikinglycdn.com/files/c299e47f-083c-4c07-ad2c-579778fbcd74/35669082386.pdf
- https://uploads.strikinglycdn.com/files/d6f6d09e-432b-4485-8041-9a34c3ceca7d/jidonufu.pdf
- https://cdn.shopify.com/s/files/1/0431/9520/3745/files/lajiravelogatal.pdf
- https://cdn.shopify.com/s/files/1/0478/4553/9999/files/51748039208.pdf
- https://cdn.shopify.com/s/files/1/0437/5370/1525/files/37774583473.pdf
- https://cdn.shopify.com/s/files/1/0485/3222/6203/files/11441275156.pdf
- https://cdn.shopify.com/s/files/1/0266/9068/3069/files/notokukoloforegetujukoliz.pdf
- https://cdn.shopify.com/s/files/1/0431/0233/9232/files/comment_connecter_une_manette_ps3_sur_android.pdf
- https://cdn.shopify.com/s/files/1/0457/6237/9940/files/lebanusaxuruzowotopapize.pdf
- https://cdn.shopify.com/s/files/1/0268/9024/0179/files/78970406444.pdf
Embedded domains
- cctraff.ru
- site-1038884.mozfiles.com
- site-1041770.mozfiles.com
- site-1040563.mozfiles.com
- site-1040200.mozfiles.com
- site-1043408.mozfiles.com
- uploads.strikinglycdn.com
- site-1039215.mozfiles.com
- site-1044162.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report