SUSPICIOUS — 4029630.pdf
SUSPICIOUS — 4029630.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
841c1bbfe86f6455d68f7a1ba2fc38776e5fe7779a2f3d0dbbec15c44483f4bb - SHA-1:
68d59337e3c7a9b594742f59796f4fc8d31c795f - MD5:
51568d234add56ae1dc9eabebe40e1f2 - ssdeep:
768:8gGzpDOp01tgxo0qNsxvJ/yHHo2ariBzp0IfzYfjIsfW8LOwr6VtKPBrg+cI:ZGFKpBvJkb9Bt0Uzq7O8kuBrtcI - TLSH:
T124327DF31097DD8C3B8E6B436DAA04A974A9D2CA5932D39044CD66AD80BC6FC7F00961 - Submitted as: 4029630.pdf
- File type: pdf · Size: 45682 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=%D1%80%D0%B5%D1%88%D0%B5%D0%B1%D0%BD%D0%B8%D0%BA%20%D0%BF%D0%BE%20%D0%B1%D0%B0%D1%88%D0%BA%D0%B8%D1%80%D1%81%D0%BA%D0%BE%D0%BC%D1%83%206%20%D0%BA%D0%BB%D0%B0%D1%81%D1%81, https://site-1039570.mozfiles.com/files/1039570/bigotedegogagozam.pdf, https://site-1043760.mozfiles.com/files/1043760/tukaxiluwukotu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=%D1%80%D0%B5%D1%88%D0%B5%D0%B1%D0%BD%D0%B8%D0%BA%20%D0%BF%D0%BE%20%D0%B1%D0%B0%D1%88%D0%BA%D0%B8%D1%80%D1%81%D0%BA%D0%BE%D0%BC%D1%83%206%20%D0%BA%D0%BB%D0%B0%D1%81%D1%81
- https://site-1039570.mozfiles.com/files/1039570/bigotedegogagozam.pdf
- https://site-1043760.mozfiles.com/files/1043760/tukaxiluwukotu.pdf
- https://site-1039959.mozfiles.com/files/1039959/58674616459.pdf
- https://site-1042103.mozfiles.com/files/1042103/tital.pdf
- https://site-1040224.mozfiles.com/files/1040224/netunedasijutasomovug.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f877362d286c.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f8718b4395c6.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f873d0b44ed4.pdf
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f87885250d2c.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f879d78c28c6.pdf
- https://site-1041864.mozfiles.com/files/1041864/26775499573.pdf
- https://site-1039270.mozfiles.com/files/1039270/47322160624.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/lerapik.pdf
- https://gonerogad.weebly.com/uploads/1/3/1/4/131438616/lazonuwiraw.pdf
- https://kuwofepex.weebly.com/uploads/1/3/2/7/132740654/fc1f70facd.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f8719a28b346.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f87532fd3019.pdf
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f878cb4f1cf4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1039570.mozfiles.com
- site-1043760.mozfiles.com
- site-1039959.mozfiles.com
- site-1042103.mozfiles.com
- site-1040224.mozfiles.com
- cdn-cms.f-static.net
- site-1041864.mozfiles.com
- site-1039270.mozfiles.com
- dirigesibujov.weebly.com
- gonerogad.weebly.com
- kuwofepex.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report