SUSPICIOUS — 8467407.pdf
SUSPICIOUS — 8467407.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7c363dc98d7b183c0678e3769700c35596756cd273b63e211bca1e30a0a61606 - SHA-1:
f2d648874bbae9fafd4368d00ccb9fa3c6d70af5 - MD5:
4e958283c31fa388185873f93eb4aca0 - ssdeep:
768:fgGzpDupYHHf07JkUMoBpTh70g7U88UkOnDu9vCAgm5HrWZmBNn4rqnjcLhbnGMz:oGFqpBWOy9v/5HOmBNYqIhbnGM1nx - TLSH:
T13D329DF354A3ED8C7A8BAB13ADEB05A95489C74CB136D760048CB72DD4BC5BC6E50460 - Submitted as: 8467407.pdf
- File type: pdf · Size: 45604 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=nacho%20libre%20parents%20guide, https://uploads.strikinglycdn.com/files/f40f8973-050f-4df0-a9f7-fa516fe6046e/tifiwisowizidezota.pdf, https://uploads.strikinglycdn.com/files/c70f2930-8bc1-46d1-9000-c2454aeaa6dd/67926590724.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=nacho%20libre%20parents%20guide
- https://uploads.strikinglycdn.com/files/f40f8973-050f-4df0-a9f7-fa516fe6046e/tifiwisowizidezota.pdf
- https://uploads.strikinglycdn.com/files/c70f2930-8bc1-46d1-9000-c2454aeaa6dd/67926590724.pdf
- https://uploads.strikinglycdn.com/files/578c038a-785a-471a-ab21-6e92cbba1f68/xipemijipopabijupuzofadip.pdf
- https://uploads.strikinglycdn.com/files/91c3ef96-76a2-4675-8ce9-3b2fddee5a42/12041496825.pdf
- https://site-1038954.mozfiles.com/files/1038954/kibusololijiki.pdf
- https://site-1038440.mozfiles.com/files/1038440/57522730060.pdf
- https://site-1038811.mozfiles.com/files/1038811/mulelosaso.pdf
- https://site-1041489.mozfiles.com/files/1041489/46274683228.pdf
- https://cdn.shopify.com/s/files/1/0476/3271/1846/files/kajozubaf.pdf
- https://cdn.shopify.com/s/files/1/0435/8501/1869/files/44792869238.pdf
- https://cdn.shopify.com/s/files/1/0498/0483/7018/files/lesusubi.pdf
- https://cdn.shopify.com/s/files/1/0477/0414/6076/files/wiselisu.pdf
- https://cdn.shopify.com/s/files/1/0479/3597/9676/files/introduction_to_mechanics_by_kleppner_and_kolenkow_solutions.pdf
- https://cdn-cms.f-static.net/uploads/4366324/normal_5f8780164be78.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f8772435e2c5.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f872c8628f3f.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f8764e56d046.pdf
- https://cdn-cms.f-static.net/uploads/4367650/normal_5f8773241d908.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/pokobu-pidoror-pekirez.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/bifulep-giwoxa.pdf
- https://rutaluxunenore.weebly.com/uploads/1/3/0/7/130740368/2182487.pdf
- https://cdn-cms.f-static.net/uploads/4367627/normal_5f874ae63b64d.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f8765e3c0e03.pdf
- https://cdn-cms.f-static.net/uploads/4369164/normal_5f87a08c3df21.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1038954.mozfiles.com
- site-1038440.mozfiles.com
- site-1038811.mozfiles.com
- site-1041489.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- zoxuzuxebexot.weebly.com
- zesopupejilit.weebly.com
- rutaluxunenore.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report