SUSPICIOUS — 90d5087ac7.pdf
SUSPICIOUS — 90d5087ac7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
74c22fb55f70400b762bc0d3df7ef1f623536f65eabaed54143723dedc55039a - SHA-1:
7dbb0032167da79865f2b9cac5c661663e8838f0 - MD5:
e3923b389b12af03978dcd5929935389 - ssdeep:
768:kgGzpD1/F4wu/HQR02bapdYh8NPsuEvv+pSsgo235ftls59hNrgfnrg9w90bWtB2:RGFBtQ122pdYh0SOpSs/2JftlsxgWi0Z - TLSH:
T11533BFF35067ED8CAB86AB035EE624592146C74D6217AB6009D97B3DC0BCBFCAD10D60 - Submitted as: 90d5087ac7.pdf
- File type: pdf · Size: 48651 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=tinea%20corporis%20adalah%20pdf, https://uploads.strikinglycdn.com/files/6deb7436-1f1a-4e15-9076-15fff5911f06/cummins_diesel_mileage.pdf, https://uploads.strikinglycdn.com/files/3ae49406-08ef-4a1d-960a-c411987c0815/aratrma_sorusu_nasl_yazlr.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=tinea%20corporis%20adalah%20pdf
- https://uploads.strikinglycdn.com/files/6deb7436-1f1a-4e15-9076-15fff5911f06/cummins_diesel_mileage.pdf
- https://uploads.strikinglycdn.com/files/3ae49406-08ef-4a1d-960a-c411987c0815/aratrma_sorusu_nasl_yazlr.pdf
- https://uploads.strikinglycdn.com/files/cda691d7-14e9-4bce-aa5b-cd471d886027/88336165943.pdf
- https://cdn.shopify.com/s/files/1/0485/3222/6203/files/the_things_they_carried_analysis.pdf
- https://uploads.strikinglycdn.com/files/5c3e0147-e1fc-42f6-bc51-2a84834ab4c6/belukimuwitefu.pdf
- https://uploads.strikinglycdn.com/files/98da44b1-4b2b-4cac-82fe-ccf906706dca/tascam_tsr_8_manual.pdf
- https://cdn.shopify.com/s/files/1/0506/0214/8005/files/84513327975.pdf
- https://cdn.shopify.com/s/files/1/0497/2878/2488/files/63624698672.pdf
- https://zinawadasug.weebly.com/uploads/1/3/4/3/134312837/bulodifif.pdf
- https://cdn.shopify.com/s/files/1/0500/3021/5317/files/69130221833.pdf
- https://uploads.strikinglycdn.com/files/db6bb9d2-307f-49f0-a3b1-833498a6156f/87250023889.pdf
- https://jepirozo.weebly.com/uploads/1/3/4/4/134474462/877972.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- zinawadasug.weebly.com
- jepirozo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report