SUSPICIOUS — b8df2702d53160b.pdf
SUSPICIOUS — b8df2702d53160b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
7fed528a5894720b61974c2465eecda49ed175ac645d37c9ff4818acb31a629a - SHA-1:
6defb51d114b749f279dd6de25a992de5ae07d2c - MD5:
b03af5ee4f246b18d04c20d8065c384f - ssdeep:
768:tgGzpDdpJsSJab6QwkAdR0sP9010YevVH3/sHrc6mTXVAOFP3suBWb0+B/9:OGFJp70S9I0TELQFAyf1BK0+B/9 - TLSH:
T1BA33AFF35497FD8C7A8BEB43ADEB01AA9049C74CA13B97A444D8331DD47C4ADAE00961 - Submitted as: b8df2702d53160b.pdf
- File type: pdf · Size: 49693 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=cosmos%20and%20psyche%20pdf, https://uploads.strikinglycdn.com/files/c5f0fcd7-f57b-4059-ad76-f41cd8ca27bf/71181126644.pdf, https://uploads.strikinglycdn.com/files/10d076ac-e399-4b17-adb4-95a0f631cd5c/84146420357.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=cosmos%20and%20psyche%20pdf
- https://uploads.strikinglycdn.com/files/c5f0fcd7-f57b-4059-ad76-f41cd8ca27bf/71181126644.pdf
- https://uploads.strikinglycdn.com/files/10d076ac-e399-4b17-adb4-95a0f631cd5c/84146420357.pdf
- https://uploads.strikinglycdn.com/files/78dd1471-2110-417a-aed6-186e0dc7a948/zilela.pdf
- https://uploads.strikinglycdn.com/files/8e5a81c2-f76f-4a41-adbe-1c08dfe097e0/jevuvurozo.pdf
- https://uploads.strikinglycdn.com/files/697ffa5d-db02-41b8-a4d7-b286da454590/nekikusoge.pdf
- https://cdn.shopify.com/s/files/1/0435/2661/9287/files/54432727017.pdf
- https://cdn.shopify.com/s/files/1/0435/9503/8888/files/the_funeral_of_st._bonaventure_is_a_painting_by_the_spanish_artist.pdf
- https://cdn.shopify.com/s/files/1/0498/9272/0829/files/episode_mod_apk_download_android_1.pdf
- https://cdn.shopify.com/s/files/1/0434/5331/7272/files/groovy_history_rare_photos_not_suitable_for_history_books.pdf
- https://uploads.strikinglycdn.com/files/7880e348-d2c1-4ecc-a719-d0b59e0f725d/daxeruvisivofigofetok.pdf
- https://uploads.strikinglycdn.com/files/88be2a95-5ece-4c2b-83d9-5c3dcb7b27c9/80290821000.pdf
- https://cdn.shopify.com/s/files/1/0494/6539/3319/files/15705846915.pdf
- https://cdn.shopify.com/s/files/1/0430/2707/1127/files/best_android_app_for_brainwave_entrainment.pdf
- https://cdn.shopify.com/s/files/1/0503/7942/3942/files/bls_2020_book.pdf
- https://uploads.strikinglycdn.com/files/a2d47c3b-cd77-4d91-9c1d-4acd8deafb98/21968077619.pdf
- https://uploads.strikinglycdn.com/files/9d4eaeeb-a8b8-4eca-92b1-35e37bfaffd1/27746390254.pdf
- https://uploads.strikinglycdn.com/files/31a75b68-7f3a-48ad-870c-5a79580a45d2/tugefijuribuf.pdf
- https://uploads.strikinglycdn.com/files/eac19971-a1a1-4dcc-a874-ae163f58de6e/xenapajewisalawagibejipe.pdf
- https://uploads.strikinglycdn.com/files/5173d11f-581b-4ca6-b0d2-89538213cd16/18823060125.pdf
- https://cdn.shopify.com/s/files/1/0435/0266/5892/files/93790599107.pdf
- https://cdn.shopify.com/s/files/1/0429/4557/7116/files/finufefuxijejigijav.pdf
- https://cdn.shopify.com/s/files/1/0439/0957/8904/files/de_que_se_alimentan_las_plantas_carnivoras.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report