SUSPICIOUS — 6210515.pdf
SUSPICIOUS — 6210515.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8f0fdaee671b7d0a199e681a7dd2b051e426725112c33a3789f872b5a4c590b1 - SHA-1:
bec58883712538e8b94d2fa7c9d9e10fc9539210 - MD5:
813d4a1cabb94d79c8766f4b024e5b6e - ssdeep:
1536:gGFRpbEE7/691YBMC9MlR884ny2WEcbFYnb:tFRp3aUMC9uR8AN0 - TLSH:
T13934BFF35097CC4C7A8B9B07ADBA0168A58AC7447223DEA014CC776CC4BCABD6E15951 - Submitted as: 6210515.pdf
- File type: pdf · Size: 54016 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=garden%20of%20tranquility%20osrs%20quick%20guide, https://cdn-cms.f-static.net/uploads/4366398/normal_5f900beb3808c.pdf, https://cdn-cms.f-static.net/uploads/4369509/normal_5f8859e8321ac.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=garden%20of%20tranquility%20osrs%20quick%20guide
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f900beb3808c.pdf
- https://cdn-cms.f-static.net/uploads/4369509/normal_5f8859e8321ac.pdf
- https://cdn-cms.f-static.net/uploads/4372723/normal_5f8a1fb9525a8.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f8810128895d.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f86f8f25f5e4.pdf
- https://uploads.strikinglycdn.com/files/9bd1641c-9dd5-4ece-8c22-4d385099a5fc/69296922539.pdf
- https://uploads.strikinglycdn.com/files/34f404b9-975e-4c93-b6c4-e1fd15daeede/wilfredo_lam_the_jungle.pdf
- https://uploads.strikinglycdn.com/files/113c699d-5a78-42a0-a9e6-ff5a332b82ad/que_es_altimetria.pdf
- https://cdn.shopify.com/s/files/1/0268/7247/9930/files/manuales_de_bienvenida_concepto.pdf
- https://cdn.shopify.com/s/files/1/0483/3227/5865/files/fred_perry_uk_size_guide.pdf
- https://cdn.shopify.com/s/files/1/0502/6637/4316/files/critical_thinking_ug.pdf
- https://uploads.strikinglycdn.com/files/4e2f1e70-051c-4565-8e02-6ce6332a16a8/geniropovevazidutoke.pdf
- https://uploads.strikinglycdn.com/files/d497a6fa-06ca-4dd4-a669-3f7bbf88d21d/migogovefidenuge.pdf
- https://uploads.strikinglycdn.com/files/0945f437-ca95-4ed0-af8b-7ac91938f0b5/87721121630.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f8a313585528.pdf
- https://cdn-cms.f-static.net/uploads/4375690/normal_5f8d0920b910d.pdf
- https://cdn-cms.f-static.net/uploads/4377908/normal_5f8c6997f2565.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f894272dc9ae.pdf
- https://cdn-cms.f-static.net/uploads/4389355/normal_5f901397a8762.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report