SUSPICIOUS — 6662e52.pdf
SUSPICIOUS — 6662e52.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
76235ce39e75737dfec33f48afde9501323f65cd6ac62adad0dbcb4e4529660c - SHA-1:
2f9cbc7c001c71b9b823941669002b922df26fb5 - MD5:
adf194e4c3616ca592639d934fc25918 - ssdeep:
768:KwgGzpDZp+DOzxnV7SP2bl9hUc+E3a0o3fvCD0RG0uowkjyBhBIyRj/WG303X1lS:SGFtpzzxnVm00RG0zjyBhBIu1303FyZ - TLSH:
T1FB328DF35093ED8C7A87AB036EEB1519A049E74961729B71508C3B2CC5BC77C6E11E60 - Submitted as: 6662e52.pdf
- File type: pdf · Size: 43706 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pretrial%20memorandum%20example, https://cdn.shopify.com/s/files/1/0484/6623/1446/files/auto_focus_binoculars_australia.pdf, https://cdn.shopify.com/s/files/1/0499/1290/5896/files/cfi_oral_exam_guide.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pretrial%20memorandum%20example
- https://cdn.shopify.com/s/files/1/0484/6623/1446/files/auto_focus_binoculars_australia.pdf
- https://cdn.shopify.com/s/files/1/0499/1290/5896/files/cfi_oral_exam_guide.pdf
- https://cdn.shopify.com/s/files/1/0498/7751/6443/files/best_calculator_for_calculus.pdf
- https://cdn.shopify.com/s/files/1/0498/7371/5358/files/mesafinutijoj.pdf
- https://buluzuzumaz.weebly.com/uploads/1/3/1/6/131636727/firija.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/275d76c8d20.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f879a3b942f0.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f8743da80cb6.pdf
- https://uploads.strikinglycdn.com/files/f497522d-070e-4fc1-a271-389ce7aa5748/xutovo.pdf
- https://uploads.strikinglycdn.com/files/604073df-066b-41ac-bc1f-569b89fe999e/tanidonujijuwod.pdf
- https://uploads.strikinglycdn.com/files/50846ed1-9292-4d69-8e6c-6655eefc54fc/bilosavunuzesi.pdf
- https://uploads.strikinglycdn.com/files/c7550947-109d-48ad-8894-758a46f0e19b/tafesexagefubopis.pdf
- https://uploads.strikinglycdn.com/files/4025416f-9e92-4f72-aae3-5cada5d51ed7/69503613465.pdf
- https://cdn.shopify.com/s/files/1/0498/0650/8186/files/linujitotobidirikomap.pdf
- https://cdn.shopify.com/s/files/1/0502/5447/9515/files/reasoning_with_democratic_values.pdf
- https://cdn.shopify.com/s/files/1/0496/0118/3896/files/greenlee_primary_school_spruce_pine_nc.pdf
- https://cdn.shopify.com/s/files/1/0434/7704/1304/files/free_vpn_for_android_phone_download.pdf
- https://cdn.shopify.com/s/files/1/0500/1602/6815/files/electric_circuit_diagram_worksheet_answers.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- buluzuzumaz.weebly.com
- vewutaniwem.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report