SUSPICIOUS — 26941151113.pdf
SUSPICIOUS — 26941151113.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
5ee989234d30d335fccaf6c2e1547f5ea512d442b8ede7058228af4ad9a67851 - SHA-1:
a4ee8fcfc2651a031a7361be23303f6f35238329 - MD5:
8ab564b1e8bcb0843a94511cf1e7a36e - ssdeep:
1536:OGFqeC81FRoTLkSvlG4zOhX7ZblPARg9:3FqeDtoToS9G4zOhX7ZGA - TLSH:
T1ED339EF310A7EC8D7A89AB036DBB24695406C78C6127DA60989C373CD5BC5FCBE50960 - Submitted as: 26941151113.pdf
- File type: pdf · Size: 50931 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=staad+pro+v8i+manual, https://cdn.shopify.com/s/files/1/0485/7875/6768/files/65982760747.pdf, https://cdn.shopify.com/s/files/1/0434/6285/2761/files/didowinojig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=staad+pro+v8i+manual
- https://cdn.shopify.com/s/files/1/0485/7875/6768/files/65982760747.pdf
- https://cdn.shopify.com/s/files/1/0434/6285/2761/files/didowinojig.pdf
- https://cdn.shopify.com/s/files/1/0491/9351/7222/files/46840245256.pdf
- https://cdn.shopify.com/s/files/1/0479/0216/3110/files/sepewimowol.pdf
- https://cdn.shopify.com/s/files/1/0434/7179/8436/files/let_teenager_try_adulthood.pdf
- https://cdn.shopify.com/s/files/1/0484/1232/8094/files/kidisokudepu.pdf
- https://cdn.shopify.com/s/files/1/0434/5049/9222/files/ben_browder_guardians_of_the_galaxy.pdf
- https://cdn.shopify.com/s/files/1/0436/8154/6390/files/95211323162.pdf
- https://cdn.shopify.com/s/files/1/0484/7131/0490/files/leeds_drive_in_radio_station.pdf
- https://cdn.shopify.com/s/files/1/0432/3649/1431/files/zejasu.pdf
- https://cdn.shopify.com/s/files/1/0432/4258/6269/files/tarozaximavupuzexulu.pdf
- https://cdn.shopify.com/s/files/1/0485/3222/6203/files/21133662136.pdf
- https://uploads.strikinglycdn.com/files/bd5ed99e-fc3d-44fd-b18e-728608dc2170/dibowugeseniwike.pdf
- https://uploads.strikinglycdn.com/files/a87fcdb7-36ed-4dec-8e73-2d2dbe92ce00/69813109880.pdf
- https://uploads.strikinglycdn.com/files/39e9cf2f-1dab-4025-997a-566b1e58ea52/10051605431.pdf
- https://uploads.strikinglycdn.com/files/cb1f73d9-b91b-4cfa-8043-759245a63a46/rekikifumorurak.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report