SUSPICIOUS — 2440745.pdf
SUSPICIOUS — 2440745.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6a72b18a62f2f627c9fce48218a6fa5f85958d43b10cf27019ab7b73a92ac9c3 - SHA-1:
b662642f769649c58ff10e063ffc02e0614cf1b9 - MD5:
94dacb25dcfad3f43ac3a4d050499185 - ssdeep:
1536:RGFOeLSak3dk7dWW3C0E2TuOMXvwgogFw9zkqq:0FOelk3dk7dlP3uOMvwgoCwRkv - TLSH:
T181349EF310A7DD8C3A8EEB03A9BB109A554AD74D61229A50448C3B2DD5BC7BD3E10A16 - Submitted as: 2440745.pdf
- File type: pdf · Size: 56358 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=describe%20a%20picture%20esl%20pdf, https://cdn.shopify.com/s/files/1/0438/4122/4869/files/japogowaniku.pdf, https://cdn.shopify.com/s/files/1/0266/8570/2319/files/muvolesoxe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=describe%20a%20picture%20esl%20pdf
- https://cdn.shopify.com/s/files/1/0438/4122/4869/files/japogowaniku.pdf
- https://cdn.shopify.com/s/files/1/0266/8570/2319/files/muvolesoxe.pdf
- https://cdn.shopify.com/s/files/1/0500/2988/7645/files/nestogen_0-6_months_instruction.pdf
- https://cdn.shopify.com/s/files/1/0494/4812/4575/files/ramble_on_led_zeppelin_lyrics.pdf
- https://uploads.strikinglycdn.com/files/f96d81fa-2ba1-494c-a0d3-8cd634cde849/ps1_bios_scph1001.bin_download.pdf
- https://uploads.strikinglycdn.com/files/795394be-9429-4731-8575-d02d78b61700/wemulefirisateg.pdf
- https://uploads.strikinglycdn.com/files/70bfbef3-2f36-447e-888f-1a4216362dfa/lakilavomolum.pdf
- https://uploads.strikinglycdn.com/files/23cc8268-4f45-422b-858f-7eb03fe02a9e/34338885071.pdf
- https://cdn.shopify.com/s/files/1/0493/1167/8623/files/momekugi.pdf
- https://cdn.shopify.com/s/files/1/0495/4646/1336/files/crystal_reports_isnull_date.pdf
- https://cdn.shopify.com/s/files/1/0438/4414/1218/files/galuzusumukom.pdf
- https://cdn.shopify.com/s/files/1/0500/3165/7130/files/esge_capsule_endoscopy_guidelines.pdf
- https://uploads.strikinglycdn.com/files/d1afc246-1763-40a2-b196-cd80ee5441d0/97803319403.pdf
- https://uploads.strikinglycdn.com/files/8e3c1e2a-69a8-4949-8d87-fe089f444667/53624503747.pdf
- https://uploads.strikinglycdn.com/files/b278f703-2e50-4d00-b3de-d8ee3275db6b/tirajamuxuwiluz.pdf
- https://uploads.strikinglycdn.com/files/612f9058-a9a3-4765-91b9-e120d0de619f/57727921979.pdf
- https://uploads.strikinglycdn.com/files/2ebcf0c4-325d-470e-857b-d8b6e217ab95/54370055119.pdf
- https://uploads.strikinglycdn.com/files/3c5d564e-0b27-444d-8c51-5dfdc033236d/botogisodidajex.pdf
- https://uploads.strikinglycdn.com/files/a0918184-4b46-4336-b254-460dd8dca07b/54153551657.pdf
- https://cdn.shopify.com/s/files/1/0500/0370/6006/files/android_dashboard_ui_kit.pdf
- https://cdn.shopify.com/s/files/1/0266/9124/0122/files/kelibelajozenefu.pdf
- https://cdn.shopify.com/s/files/1/0499/3826/8318/files/dent_mod_apk_unlimited_money.pdf
- https://cdn.shopify.com/s/files/1/0501/0613/8787/files/download_game_mod_apk_ghost_battle_2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report