SUSPICIOUS — 74608082.pdf
SUSPICIOUS — 74608082.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
8545238baf63dd7d9d758ac8d775d487fa8bbbac6dd1f4bbdc4c0d4072ed7f7e - SHA-1:
36966baf411649496cafb2f1b7bf9174c7f8f5ec - MD5:
cab4400134d97cac9d65accf19dbaa2b - ssdeep:
1536:cGFp9FvyXMK/WrbZc6KqYqznGerq8ELv:5Fp9FqXMK+9zGerHEz - TLSH:
T18C34C0F31143ED8CB78BE7035EE62469614AC38E243196A555CC336CC4BC6FE6E11A21 - Submitted as: 74608082.pdf
- File type: pdf · Size: 57265 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=configure+azure+ad+connect+with+adfs+step+by+step, https://site-1043295.mozfiles.com/files/1043295/rufiku.pdf, https://site-1040145.mozfiles.com/files/1040145/36647684331.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=configure+azure+ad+connect+with+adfs+step+by+step
- https://site-1043295.mozfiles.com/files/1043295/rufiku.pdf
- https://site-1040145.mozfiles.com/files/1040145/36647684331.pdf
- https://site-1043837.mozfiles.com/files/1043837/bizonulod.pdf
- https://site-1039779.mozfiles.com/files/1039779/88191257975.pdf
- https://uploads.strikinglycdn.com/files/00a58bb2-83a5-4a3b-ae2f-c5515f4fb0d2/xevajet.pdf
- https://uploads.strikinglycdn.com/files/c9b57db7-ee15-49c0-8caa-fd260019930c/nusunidupunofogabepi.pdf
- https://uploads.strikinglycdn.com/files/1b7b0bd9-399e-4cb8-9411-fc0a3e57eb12/sazojumepuvuniziwok.pdf
- https://uploads.strikinglycdn.com/files/deac1ca5-8d3a-408b-bbfe-4e8e948100c5/1534700953.pdf
- https://uploads.strikinglycdn.com/files/8fc270e1-ca89-4b8f-8d20-c9334f2e1c5c/6154382072.pdf
- https://uploads.strikinglycdn.com/files/2f79a9a0-bc04-4232-9c16-c34b7bd089cc/puvir.pdf
- https://uploads.strikinglycdn.com/files/78ef689d-861d-4a13-bc0c-a6f878760666/rukofepajubuvusunar.pdf
- https://cdn.shopify.com/s/files/1/0497/1796/9057/files/weather_pro_apk.pdf
- https://cdn.shopify.com/s/files/1/0431/5335/8999/files/guzevom.pdf
- https://cdn.shopify.com/s/files/1/0435/3182/9412/files/g_minor_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1043295.mozfiles.com
- site-1040145.mozfiles.com
- site-1043837.mozfiles.com
- site-1039779.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report