SUSPICIOUS — 4704680.pdf
SUSPICIOUS — 4704680.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
3dc486af14e5e1252bf5c1b99df6561779f33e04fcaa35e62c08b24eacf66efb - SHA-1:
2fa52d43114ffd2ceb324bd6c48390357af6dd40 - MD5:
fce7fe1e6b3f57007100d4b677fead31 - ssdeep:
768:GgGzpDsKpAPjSeFTP4OQLJ27uKtnbJL/RKD9dKQVOhPD2JhhXU:TGFLpA8GVRCdDVOhPD2JLU - TLSH:
T1A2306CF31097EC8C7B8E5F03AEAB115DA28BC78861379790449C262CD47CAED7E40965 - Submitted as: 4704680.pdf
- File type: pdf · Size: 36967 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=libro%20dibujo%20tecnico%20bachillerato%20pdf, https://site-1043047.mozfiles.com/files/1043047/xixavarozovefot.pdf, https://site-1043767.mozfiles.com/files/1043767/44386634142.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=libro%20dibujo%20tecnico%20bachillerato%20pdf
- https://site-1043047.mozfiles.com/files/1043047/xixavarozovefot.pdf
- https://site-1043767.mozfiles.com/files/1043767/44386634142.pdf
- https://site-1042271.mozfiles.com/files/1042271/45001270611.pdf
- https://site-1039840.mozfiles.com/files/1039840/50176272412.pdf
- https://site-1039924.mozfiles.com/files/1039924/degavezawurafifajedez.pdf
- https://uploads.strikinglycdn.com/files/b553225f-363a-4e10-a733-4a280bbfbcd3/11457574695.pdf
- https://uploads.strikinglycdn.com/files/e439f9e4-1af3-410c-8e4d-e3abbd794051/fibijire.pdf
- https://uploads.strikinglycdn.com/files/807c5c80-6c15-42c0-9152-7909b6909f12/26406044781.pdf
- https://cdn-cms.f-static.net/uploads/4370092/normal_5f88dc8198069.pdf
- https://cdn-cms.f-static.net/uploads/4367919/normal_5f887a1ab416d.pdf
- https://cdn-cms.f-static.net/uploads/4365657/normal_5f88ca8789268.pdf
- https://cdn-cms.f-static.net/uploads/4370989/normal_5f89025d574b4.pdf
- https://cdn-cms.f-static.net/uploads/4367303/normal_5f87df01f3070.pdf
- https://uploads.strikinglycdn.com/files/4bf97f73-d4a0-4efa-b613-5e3be51a1912/mosoxobibavevepakate.pdf
- https://uploads.strikinglycdn.com/files/c9398158-1aa4-4b33-b36d-93722d8b8951/bovur.pdf
- https://uploads.strikinglycdn.com/files/ed8467bd-beed-42ae-9fe5-f91d93bae906/lijojaluwezuganub.pdf
- https://uploads.strikinglycdn.com/files/741ebaf4-bd22-4d84-a78a-b92f3c62d775/jerixime.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/408cbd41f222.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/sidobojugonuxexoz.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/9594994.pdf
- https://rabexowubomisuw.weebly.com/uploads/1/3/1/4/131407155/teduzaxovez-wemojakemoma.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/afa7ee664f026.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f87167c603f1.pdf
- https://cdn-cms.f-static.net/uploads/4367301/normal_5f89039be5a26.pdf
Embedded domains
- cctraff.ru
- site-1043047.mozfiles.com
- site-1043767.mozfiles.com
- site-1042271.mozfiles.com
- site-1039840.mozfiles.com
- site-1039924.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- jiwepurojal.weebly.com
- dutitujazekap.weebly.com
- mojivimimujovo.weebly.com
- rabexowubomisuw.weebly.com
- zesopupejilit.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report