SUSPICIOUS — 48b60421ef6.pdf
SUSPICIOUS — 48b60421ef6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
5b52328d15b28080999f2249c5d263bcc1cef899bdb367dc40db11395edd6754 - SHA-1:
ab3aa54f4de42ba5f20b99919d56bfac43151974 - MD5:
3296e89df348576260f55669944a5463 - ssdeep:
768:wgGzpDm1KpUOLflWNqNHIIj3eI3X1mg8C7y1iN4z/Li2t+nD0T0k:dGFaxapjuyXPTG4w/Lt+nD0T0k - TLSH:
T10E319EF75053ED4C7A8B9B1729E51019218ACB4A3033ABA454D87BBCC5FC7BD6E10960 - Submitted as: 48b60421ef6.pdf
- File type: pdf · Size: 41991 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=super%20mario%20unblocked%20games%206969, https://cdn.shopify.com/s/files/1/0498/0136/3619/files/26623290142.pdf, https://uploads.strikinglycdn.com/files/c8b1c194-1698-4877-9099-875c801aff71/30687846283.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=super%20mario%20unblocked%20games%206969
- https://cdn.shopify.com/s/files/1/0498/0136/3619/files/26623290142.pdf
- https://s3.amazonaws.com/xenavuxa/mri_t1_vs_t2_explained.pdf
- https://uploads.strikinglycdn.com/files/c8b1c194-1698-4877-9099-875c801aff71/30687846283.pdf
- https://cdn-cms.f-static.net/uploads/4370263/normal_5f9299f9ed128.pdf
- https://vafumigoku.weebly.com/uploads/1/3/1/3/131384305/mozes.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f887b55652fa.pdf
- https://s3.amazonaws.com/vekodupiwarobi/81121873135.pdf
- https://s3.amazonaws.com/luramamelolem/dihybrid_cross_practice_problems_answers.pdf
- https://cdn.shopify.com/s/files/1/0499/9764/3927/files/58914100616.pdf
- https://s3.amazonaws.com/dejolavubukugeb/vazarezusa.pdf
- https://cdn-cms.f-static.net/uploads/4382421/normal_5f8c15964de27.pdf
- https://s3.amazonaws.com/bezegoluzose/meaning_of_numbers_in_the_bible_chart.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- vafumigoku.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report