SUSPICIOUS — 8e66ca.pdf
SUSPICIOUS — 8e66ca.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
613a1135c188c4116a3f8b98126662e830756265d3560e3be79f16ba7dba0cf9 - SHA-1:
7a296c635de10aeaf1a6d93d7f2604ca3d403dcd - MD5:
1515e53879e7d0f13d69c77987573e47 - ssdeep:
768:+gGzpDMIyazXyNZTGHoM5LBI94tL8LG/eyC8GkP9WBr2h:7GFwIqHTGHoSuStj/Cg9Kr2h - TLSH:
T17031AFF3A167DE8C7A92AB0359E624A9214AC28C7133976454CC7F7DC87C7AC6E00970 - Submitted as: 8e66ca.pdf
- File type: pdf · Size: 40047 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=windows%2010%20explorer%20pdf%20preview%20pane%20not%20working, https://cdn-cms.f-static.net/uploads/4378605/normal_5f9272de64469.pdf, https://uploads.strikinglycdn.com/files/fd56c3c0-0892-4983-9b60-279fddb467e7/79775155818.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=windows%2010%20explorer%20pdf%20preview%20pane%20not%20working
- https://cdn-cms.f-static.net/uploads/4378605/normal_5f9272de64469.pdf
- https://s3.amazonaws.com/rekorewexidiwo/52162462555.pdf
- https://s3.amazonaws.com/felasorarabipis/payroll_management_software.pdf
- https://uploads.strikinglycdn.com/files/fd56c3c0-0892-4983-9b60-279fddb467e7/79775155818.pdf
- https://uploads.strikinglycdn.com/files/086426c9-fb41-464f-96a0-ad65ba26387c/xumuje.pdf
- https://korumarivaz.weebly.com/uploads/1/3/4/5/134506991/3374198.pdf
- https://uploads.strikinglycdn.com/files/8f5e7742-eb26-47a8-87a3-d96622d93eec/regujexevunagejomuwogun.pdf
- https://s3.amazonaws.com/pazifetanegapu/pep_rally_games_for_high_schoolers.pdf
- https://s3.amazonaws.com/tojabixefova/97980506911.pdf
- https://cdn-cms.f-static.net/uploads/4403537/normal_5f99ccba7833f.pdf
- https://s3.amazonaws.com/subud/bosch_spare_parts_catalogue.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- korumarivaz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report