SUSPICIOUS — 7e336e.pdf
SUSPICIOUS — 7e336e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9d53c64dae95feab1e18e35efc3c7e52489f6569daae0517bfee894163afd37c - SHA-1:
fcd37b1e614aaab1c6a01c41ecbf00a3e1b079e6 - MD5:
ab357afcb7aa26ad5669145388400e8a - ssdeep:
768:ogGzpDMKpaKfiLY9fBgCiWf/nTUQWUm9URpbNXNr6YuJoh:lGFHp2Y/TRZm9UVN3uJoh - TLSH:
T137307CF350A7DD8C7AC7A783BDA61489A189D38C712397B004987B2DC4B82BD7F54861 - Submitted as: 7e336e.pdf
- File type: pdf · Size: 37500 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=nutri%C3%A7%C3%A3o%20animal%20andriguetto%20comprar, https://cdn-cms.f-static.net/uploads/4366343/normal_5f8748a670b79.pdf, https://cdn-cms.f-static.net/uploads/4367005/normal_5f8731fe4b124.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=nutri%C3%A7%C3%A3o%20animal%20andriguetto%20comprar
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f8748a670b79.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f8731fe4b124.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f86fa0a70e46.pdf
- https://uploads.strikinglycdn.com/files/46c6a398-25a7-45db-9813-5f52b6e3d7ba/16435861734.pdf
- https://uploads.strikinglycdn.com/files/44d0f273-8824-4412-8c8b-ebf0dd16d0ac/18546987861.pdf
- https://site-1040263.mozfiles.com/files/1040263/26165026826.pdf
- https://site-1037177.mozfiles.com/files/1037177/rifenoludasaxamuzozife.pdf
- https://site-1039194.mozfiles.com/files/1039194/5287156960.pdf
- https://site-1037882.mozfiles.com/files/1037882/minawinozisogijuj.pdf
- https://site-1040008.mozfiles.com/files/1040008/9798640905.pdf
- https://cdn.shopify.com/s/files/1/0482/8531/9332/files/paintball_sentry_gun.pdf
- https://cdn.shopify.com/s/files/1/0500/0436/1366/files/melikamomop.pdf
- https://cdn.shopify.com/s/files/1/0493/9789/1228/files/swannview_app_not_logging_in.pdf
- https://cdn.shopify.com/s/files/1/0497/8045/7623/files/husky_ratchet_set_instructions.pdf
- https://cdn.shopify.com/s/files/1/0501/1505/1685/files/section_11.2_from_dna_to_protein_worksheet_answers.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/gurom.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3079835.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1040263.mozfiles.com
- site-1037177.mozfiles.com
- site-1039194.mozfiles.com
- site-1037882.mozfiles.com
- site-1040008.mozfiles.com
- cdn.shopify.com
- jeponiruwapin.weebly.com
- zoxuzuxebexot.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report