SUSPICIOUS — 41458450182.pdf
SUSPICIOUS — 41458450182.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4039f69d06208d0d080ff10165c8e944af4857a23028671d9231e8506c560e24 - SHA-1:
1f453387201b898de397a26fce22161a4a761204 - MD5:
addf5cd50d4766a4a9c2cfa99bc680d1 - ssdeep:
768:agGzpDyZtt6ke/nW7UKyxAHBEOE+VNQnW5DFiotjXr4t7ZPZZaWjHzvqQX:HGF+w+7wg2EmW5DA4jXctdaWjHrqQX - TLSH:
T15932BFF3549BED8CB74A9B4B58EB0458614AC3C97132D66058CC763CC47C6BCBE12A61 - Submitted as: 41458450182.pdf
- File type: pdf · Size: 47402 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=q7+smartwatch+3326+manual, https://cdn.shopify.com/s/files/1/0434/0360/8214/files/mibekufoz.pdf, https://cdn.shopify.com/s/files/1/0430/6167/4133/files/3869365249.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=q7+smartwatch+3326+manual
- https://cdn.shopify.com/s/files/1/0431/8062/1984/files/sasaza.pdf
- https://cdn.shopify.com/s/files/1/0434/0360/8214/files/mibekufoz.pdf
- https://cdn.shopify.com/s/files/1/0430/6167/4133/files/3869365249.pdf
- https://site-1036819.mozfiles.com/files/1036819/jenirudugusagewunesapo.pdf
- https://site-1036646.mozfiles.com/files/1036646/jiwibotixuvijuno.pdf
- https://site-1036812.mozfiles.com/files/1036812/29192464847.pdf
- https://site-1037221.mozfiles.com/files/1037221/8645263116.pdf
- https://uploads.strikinglycdn.com/files/2e42f810-cfb1-4736-a7c5-a49d85516a7a/51198758999.pdf
- https://uploads.strikinglycdn.com/files/cf85cb28-c5fb-4f7d-bea4-528d8b697fcd/tutuloki.pdf
- https://uploads.strikinglycdn.com/files/2d636b8f-e6e8-4cae-9bc0-55c3207e4366/33519674638.pdf
- https://uploads.strikinglycdn.com/files/0e2a54b7-2f7f-4093-995e-61b670031a6f/tilunu.pdf
- https://uploads.strikinglycdn.com/files/c51062ba-f1f9-4096-8d83-8d4736a77ecc/junan.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1036819.mozfiles.com
- site-1036646.mozfiles.com
- site-1036812.mozfiles.com
- site-1037221.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report