SUSPICIOUS — 6787318.pdf
SUSPICIOUS — 6787318.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
82e2b46a430f73d1a586c3d575fc3e1897fe55e6b6ebeb936a0ef67b1dc8b21e - SHA-1:
56d9fcf4a5edd14951ed1f84dcb3ac5157e100ba - MD5:
e2ffdce566e3e4f387b34151235e5daf - ssdeep:
768:VgGzpDDpLFPFy+5Zkn+SuXsRZmXgx9/se7JX5CrWS7AxZcooNv:GGFXpY9Ee95CrWS7YqooNv - TLSH:
T1C3308CF344A7EC4C7B8A9B13ADE7006A6186C3883136D7A045C83B6CD57C6BDBE11961 - Submitted as: 6787318.pdf
- File type: pdf · Size: 38010 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=historia%20universal%20contemporanea%20humberto%20sanchez%20pdf, https://cdn.shopify.com/s/files/1/0499/9086/0962/files/like_im_gonna_lose_you_music_download.pdf, https://cdn.shopify.com/s/files/1/0498/7594/3585/files/nyc_doe_calendar_2015-16.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=historia%20universal%20contemporanea%20humberto%20sanchez%20pdf
- https://cdn.shopify.com/s/files/1/0499/9086/0962/files/like_im_gonna_lose_you_music_download.pdf
- https://cdn.shopify.com/s/files/1/0498/7594/3585/files/nyc_doe_calendar_2015-16.pdf
- https://cdn.shopify.com/s/files/1/0484/2632/0024/files/gudunizaxegorof.pdf
- https://cdn.shopify.com/s/files/1/0500/1353/6426/files/ifb_washing_machine_digital_6kg_manual.pdf
- https://cdn.shopify.com/s/files/1/0492/7756/7132/files/28270255925.pdf
- https://cdn.shopify.com/s/files/1/0266/9818/6937/files/shoulder_dolly_moving_straps_harbor_freight.pdf
- https://cdn.shopify.com/s/files/1/0266/8091/8203/files/python_interpreter_for_android_download.pdf
- https://cdn.shopify.com/s/files/1/0499/0667/9997/files/4391662428.pdf
- https://cdn.shopify.com/s/files/1/0497/9359/7601/files/bebigujinifumobiv.pdf
- https://cdn.shopify.com/s/files/1/0266/8383/4543/files/world_history_encyclopedia_online.pdf
- https://cdn.shopify.com/s/files/1/0436/7125/7241/files/boss_katana_mk2_manual.pdf
- https://cdn.shopify.com/s/files/1/0268/8427/6415/files/recurrent_neural_network_journal.pdf
- https://uploads.strikinglycdn.com/files/5ba0e212-df77-4f92-a606-cdfec9db9c31/41249018783.pdf
- https://uploads.strikinglycdn.com/files/226dfb43-f716-4ab1-bcff-3a636d2d8884/67089672091.pdf
- https://uploads.strikinglycdn.com/files/0bb8e865-03f9-488d-a904-9cf31471a0b4/vaxisikufekonemo.pdf
- https://uploads.strikinglycdn.com/files/f043c688-326d-4cc6-afce-ad27f4fd45ac/vawazofenunamevu.pdf
- https://uploads.strikinglycdn.com/files/c91c0371-03f9-4b8d-89de-f91b032af530/bosiniwosapovewudede.pdf
- https://s3.amazonaws.com/zugutixe/mirenifufobawerom.pdf
- https://s3.amazonaws.com/jobavo/reading_and_writing_grade_11.pdf
- https://s3.amazonaws.com/wilugugo/93335539118.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report