SUSPICIOUS — 2771956.pdf
SUSPICIOUS — 2771956.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
67a39c979a533a16e59201de1ed1de4b10a159d164a5a4785518c82ff247bd73 - SHA-1:
6798d9e59e90d7d8b00bfcd2f884198a4fe2d625 - MD5:
ed77166e45c901b9710cf015f55966ba - ssdeep:
768:jgGzpDopAlO9jwS7m2JZfI5zMFp6ZGFagExsmdpUGQ1ngel1pjD16G:cGFcpNagFagE6gpZQ1ng4pv16G - TLSH:
T1D3305CF34097ED4C7B8B6F17AEAB1259A44AD7896132EA90448C272DD07CAED7F00611 - Submitted as: 2771956.pdf
- File type: pdf · Size: 38425 bytes
- Verdict: suspicious (35/100)
Detections (1 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=my%20singing%20monsters%20keys, https://cdn.shopify.com/s/files/1/0438/5321/7942/files/85391182301.pdf, https://cdn.shopify.com/s/files/1/0483/3227/5865/files/39077907550.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=my%20singing%20monsters%20keys
- https://cdn.shopify.com/s/files/1/0438/5321/7942/files/85391182301.pdf
- https://cdn.shopify.com/s/files/1/0483/3227/5865/files/39077907550.pdf
- https://cdn.shopify.com/s/files/1/0428/7257/0012/files/nessus_chamber_of_sky_region_chest.pdf
- https://cdn.shopify.com/s/files/1/0483/4898/7545/files/kusopeli.pdf
- https://cdn.shopify.com/s/files/1/0437/1123/4199/files/neko_atsume_wiki.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f8717dce800f.pdf
- https://cdn-cms.f-static.net/uploads/4367650/normal_5f883ee465fae.pdf
- https://site-1039779.mozfiles.com/files/1039779/tuxizixexedulaworu.pdf
- https://site-1036785.mozfiles.com/files/1036785/85352447644.pdf
- https://site-1036957.mozfiles.com/files/1036957/masubawevojituxaxezife.pdf
- https://site-1040242.mozfiles.com/files/1040242/74493247279.pdf
- https://site-1038508.mozfiles.com/files/1038508/42432372511.pdf
- https://site-1037886.mozfiles.com/files/1037886/pasezonekulajukuno.pdf
- https://site-1043218.mozfiles.com/files/1043218/33112426379.pdf
- https://site-1040136.mozfiles.com/files/1040136/wotarodofijute.pdf
- https://site-1039515.mozfiles.com/files/1039515/bunotofu.pdf
- https://site-1045346.mozfiles.com/files/1045346/32501880733.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f86f9161093c.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f875d4390e4f.pdf
- https://cdn-cms.f-static.net/uploads/4370285/normal_5f88577e27a56.pdf
- https://cdn-cms.f-static.net/uploads/4369915/normal_5f88868fb4365.pdf
- https://cdn.shopify.com/s/files/1/0434/6380/3046/files/what_do_mealworms_eat_in_the_wild.pdf
- https://cdn.shopify.com/s/files/1/0440/7607/3125/files/78872704541.pdf
- https://cdn.shopify.com/s/files/1/0485/0244/0091/files/az_lyrics_across_the_universe.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1039779.mozfiles.com
- site-1036785.mozfiles.com
- site-1036957.mozfiles.com
- site-1040242.mozfiles.com
- site-1038508.mozfiles.com
- site-1037886.mozfiles.com
- site-1043218.mozfiles.com
- site-1040136.mozfiles.com
- site-1039515.mozfiles.com
- site-1045346.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report