SUSPICIOUS — 80f663a98e7f.pdf
SUSPICIOUS — 80f663a98e7f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
88d660cfb8999ce13a68e83645ebbee76ea1be2f08f0428dd3297f501264b2c2 - SHA-1:
a4cb8e5acfd260583ea6a8283876fbdcd4937cea - MD5:
da5f00556e5783605b531844a913c87e - ssdeep:
3072:WF0pieXdSqA3ne3kXsVyhSMZ8R4S/CXWfMWZDf4:mmVIVnGkcVtMZ8BH/Z0 - TLSH:
T1123AE1F71647ED0C7ACB9B53AE9B0195A289D78C7236A3A040AC671CC47C1BD6F21860 - Submitted as: 80f663a98e7f.pdf
- File type: pdf · Size: 100144 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=libro%20de%20guzman%20criminalistica%20pdf, https://uploads.strikinglycdn.com/files/1a342d74-f701-4221-be87-50ae9abecbf7/bemixigabekebubopidi.pdf, https://uploads.strikinglycdn.com/files/07e2c2fe-4d9a-4da0-9793-e6eca2a7a85f/download_cassiane_viva.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=libro%20de%20guzman%20criminalistica%20pdf
- https://uploads.strikinglycdn.com/files/1a342d74-f701-4221-be87-50ae9abecbf7/bemixigabekebubopidi.pdf
- https://uploads.strikinglycdn.com/files/07e2c2fe-4d9a-4da0-9793-e6eca2a7a85f/download_cassiane_viva.pdf
- https://uploads.strikinglycdn.com/files/01be5046-bc45-412f-94d2-281c0efab8ca/52256100438.pdf
- https://uploads.strikinglycdn.com/files/91846419-a103-4f70-9412-ed8792dd2c4e/66584888253.pdf
- https://cdn-cms.f-static.net/uploads/4380881/normal_5f8e973e42051.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f874fed542f0.pdf
- https://cdn-cms.f-static.net/uploads/4386086/normal_5f91fd092aa21.pdf
- https://cdn-cms.f-static.net/uploads/4374376/normal_5f8a7bb335b50.pdf
- https://cdn.shopify.com/s/files/1/0482/3731/4200/files/sadowamifekovel.pdf
- https://cdn.shopify.com/s/files/1/0500/3542/5431/files/chemical_engineering_textbook.pdf
- https://cdn.shopify.com/s/files/1/0438/5865/7430/files/dd_3.5_shadowcraft_mage.pdf
- https://uploads.strikinglycdn.com/files/70acf821-22ac-4ffd-910b-d9ab921a22c9/35076703279.pdf
- https://uploads.strikinglycdn.com/files/81df59a0-2676-4cc5-93bc-f992190b4e75/pourquoi_jai_choisi_ce_stage.pdf
- https://uploads.strikinglycdn.com/files/0dead9ea-80df-433d-b139-bb65066be9f0/83972308268.pdf
- https://uploads.strikinglycdn.com/files/d4abbbe1-b4a8-4e05-9757-9f83340e39d3/62552919156.pdf
- https://uploads.strikinglycdn.com/files/f035fd27-9822-4f90-b28d-2d8c9bafc98a/despacito_sheet_music_violin.pdf
- https://cdn.shopify.com/s/files/1/0435/0600/8216/files/estructura_del_atomo_quimica_general.pdf
- https://cdn.shopify.com/s/files/1/0504/2159/6334/files/54342808696.pdf
- https://cdn.shopify.com/s/files/1/0431/1344/7584/files/top_down_network_design.pdf
- https://cdn.shopify.com/s/files/1/0496/8480/7861/files/green_valley_kennels_byers_co.pdf
- https://cdn-cms.f-static.net/uploads/4388614/normal_5f92b22637247.pdf
- https://cdn-cms.f-static.net/uploads/4366364/normal_5f8738d951a1d.pdf
- https://cdn-cms.f-static.net/uploads/4367665/normal_5f95f8112f8e7.pdf
- https://cdn-cms.f-static.net/uploads/4369317/normal_5f905d5c575b5.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report