SUSPICIOUS — 5162277.pdf
SUSPICIOUS — 5162277.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
5591d27d72ec80ef83cca29f625400b56aaae18ecbafa56707fa940212da0c98 - SHA-1:
e81828bdabee8f862b378f87fe6008af11f1fdb0 - MD5:
53ae341af41d24c34775afdc0a24f6a2 - ssdeep:
1536:1GFC1coKusjHwnFmJR9Vyv8EKvzCjwLofmAmeYU61kyEAp:IFC1mNHwwRCUEKzCEObJYUaj - TLSH:
T19837E0F760ABED4C2A8BAB07ADE71668664DC3487236A7640CCC7B7C807C16D2F54424 - Submitted as: 5162277.pdf
- File type: pdf · Size: 72930 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=icdl%20module%202%20windows%207%20pdf, https://uploads.strikinglycdn.com/files/fc5cd86c-864b-402b-bbf6-c62f4d12851b/write_for_college_a_student_handbook.pdf, https://uploads.strikinglycdn.com/files/7fe3dfbf-5155-4750-9fd7-ff306e6c50b9/synthesizing_sources_worksheet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=icdl%20module%202%20windows%207%20pdf
- https://s3.amazonaws.com/fasanag/boylestad_12th_edition_solution.pdf
- https://s3.amazonaws.com/lewuli/vawumoselikuvi.pdf
- https://s3.amazonaws.com/felasorarabipis/68308723268.pdf
- https://uploads.strikinglycdn.com/files/fc5cd86c-864b-402b-bbf6-c62f4d12851b/write_for_college_a_student_handbook.pdf
- https://uploads.strikinglycdn.com/files/7fe3dfbf-5155-4750-9fd7-ff306e6c50b9/synthesizing_sources_worksheet.pdf
- https://cdn-cms.f-static.net/uploads/4375093/normal_5f9460ad77f8a.pdf
- https://cdn-cms.f-static.net/uploads/4372104/normal_5f8abda9ca8f4.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f890e5778239.pdf
- https://cdn-cms.f-static.net/uploads/4368219/normal_5f8aafca3af3b.pdf
- https://cdn-cms.f-static.net/uploads/4389568/normal_5f91681465058.pdf
- https://cdn-cms.f-static.net/uploads/4383792/normal_5f9421f122813.pdf
- https://uploads.strikinglycdn.com/files/f841d745-1063-4e88-9826-d0d9c2c16e70/64283003.pdf
- https://uploads.strikinglycdn.com/files/c89f4f2f-345c-42e4-abd7-9ab211fd8d3e/4584599208.pdf
- https://uploads.strikinglycdn.com/files/54edcb79-c93a-403a-aed7-df008b7a4243/71835577260.pdf
- https://uploads.strikinglycdn.com/files/c92b20b7-abc0-49b8-8591-0b3e3ed6072d/44043430603.pdf
- https://uploads.strikinglycdn.com/files/87e6e51b-8f20-443a-8368-d0c41f52fb33/rajitomofadez.pdf
- https://cdn-cms.f-static.net/uploads/4372721/normal_5f8f8cfa119f8.pdf
- https://cdn-cms.f-static.net/uploads/4379733/normal_5f8af452ed71b.pdf
- https://cdn-cms.f-static.net/uploads/4387430/normal_5f908f195ab26.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- x:\Za
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report