SUSPICIOUS — 8993613.pdf
SUSPICIOUS — 8993613.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
85573f0f69a0255ea4eee5ea2cb6fc29bb8f6a5ceff55a839eeec8269b6f9358 - SHA-1:
80fd61b5cb61142a8fb21b4d03a68d70f43af26b - MD5:
d44506564360e83fc3412844acdf471a - ssdeep:
768:sgGzpDopYgpSrPZ7gH0snNV2f70en0sWiConQ3fGyY/oosd1gd1kuRF:pGF8pt2ge0hP+QvGyY/md+fkuRF - TLSH:
T125327CF30093DD4C7ACE9F07AEAB149DA48AD7886226E350558CBB2CD47C6ED2F10561 - Submitted as: 8993613.pdf
- File type: pdf · Size: 44075 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=french%20in%2020%20lessons%20pdf, https://cdn.shopify.com/s/files/1/0435/8812/4830/files/70931909637.pdf, https://cdn.shopify.com/s/files/1/0501/1708/3286/files/download_infinite_flight_latest_version_mod_apk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=french%20in%2020%20lessons%20pdf
- https://cdn.shopify.com/s/files/1/0435/8812/4830/files/70931909637.pdf
- https://cdn.shopify.com/s/files/1/0501/1708/3286/files/download_infinite_flight_latest_version_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0435/1436/4059/files/xenejilomakakozomu.pdf
- https://cdn-cms.f-static.net/uploads/4394073/normal_5f9587ba8caeb.pdf
- https://cdn-cms.f-static.net/uploads/4368762/normal_5f88901863028.pdf
- https://s3.amazonaws.com/pugomonapoxuxe/3rd_grade_math_teks.pdf
- https://s3.amazonaws.com/xezonijida/balanced_diet_chart_for_12_year_old_child.pdf
- https://s3.amazonaws.com/bezutu/radokobomaji.pdf
- https://s3.amazonaws.com/ganubifirigevi/absorcion_de_nutrientes_en_el_aparato_digestivo.pdf
- https://s3.amazonaws.com/pujirageg/architectural_record_2018.pdf
- https://s3.amazonaws.com/tetazino/tubabebop.pdf
- https://s3.amazonaws.com/jebupofedijakuk/class_10_history_book_in_bengali.pdf
- https://s3.amazonaws.com/daraniwekamidir/92111962246.pdf
- https://s3.amazonaws.com/gaxuremewuger/25768668671.pdf
- https://cdn-cms.f-static.net/uploads/4408976/normal_5f9727d3dd481.pdf
- https://cdn-cms.f-static.net/uploads/4368745/normal_5f94da9b2761b.pdf
- https://cdn-cms.f-static.net/uploads/4370072/normal_5f9005dac0abe.pdf
- https://cdn-cms.f-static.net/uploads/4367640/normal_5f8fb2ca33dca.pdf
- https://cdn-cms.f-static.net/uploads/4369640/normal_5f88d1cb1ca67.pdf
- https://uploads.strikinglycdn.com/files/ad1793e1-5a4e-4651-8956-7b4e99f369f8/eye_care_switcher_download.pdf
- https://uploads.strikinglycdn.com/files/dcbe50a1-d94a-4cf7-8f3c-ff0c001e8901/becoming_a_supple_leopard.pdf
- https://uploads.strikinglycdn.com/files/312d72b1-6fa8-476a-b219-022c0887f3f2/nodar.pdf
- https://uploads.strikinglycdn.com/files/22d44d2e-e3c9-48f9-a6f7-25081133c8fd/lapolamawikowatolebexepo.pdf
- https://uploads.strikinglycdn.com/files/8a455240-c236-4967-9b61-f49157d5dd80/88352774582.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report