SUSPICIOUS — 1d449172748edc.pdf
SUSPICIOUS — 1d449172748edc.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a14fce03e213de285ad9bdfb76a11fc729794e9ab06f758a2f456bd70d50dca6 - SHA-1:
bb3ea731cd68862cd864881651cb66fb3f172f6a - MD5:
97052b303cacd7c6723b8d45ffd22377 - ssdeep:
768:CgGzpDaKC9Pgbk8SlGvCbiWAW+4aNExuuG9vyyqsZGpJ8dD23WZDRMmPDz:fGF+gko9vy7sZGpXWZDSSz - TLSH:
T128316DF3506BDD8D7AC79F23ADE62029654AC74C6132DB50448C772CD4BCABD6E11860 - Submitted as: 1d449172748edc.pdf
- File type: pdf · Size: 40944 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish!atmn
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=veligonda%20project%20pdf, https://cdn-cms.f-static.net/uploads/4366316/normal_5f91b16ef3e5d.pdf, https://uploads.strikinglycdn.com/files/6f0c589e-f553-4f06-9e8e-f0569ce0d89a/diablitos_de_colombia_busca_un_confi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=veligonda%20project%20pdf
- https://cdn-cms.f-static.net/uploads/4366316/normal_5f91b16ef3e5d.pdf
- https://uploads.strikinglycdn.com/files/6f0c589e-f553-4f06-9e8e-f0569ce0d89a/diablitos_de_colombia_busca_un_confi.pdf
- https://cdn.shopify.com/s/files/1/0492/3906/4742/files/spectrum_cable_tv_guide_dallas.pdf
- https://cdn-cms.f-static.net/uploads/4387712/normal_5f923be7279dd.pdf
- https://cdn-cms.f-static.net/uploads/4371266/normal_5f8f72571a5f0.pdf
- https://cdn-cms.f-static.net/uploads/4374535/normal_5f8a38e8a7da9.pdf
- https://cdn.shopify.com/s/files/1/0437/2991/1957/files/ft-7900r_mars_mod.pdf
- https://cdn.shopify.com/s/files/1/0494/0601/7692/files/alcatel_go_flip_unlocked_canada.pdf
- https://cdn-cms.f-static.net/uploads/4387716/normal_5f967b5ae72bb.pdf
- https://cdn-cms.f-static.net/uploads/4385207/normal_5f90995ff35a6.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f8a7924dea85.pdf
- https://cdn-cms.f-static.net/uploads/4382186/normal_5f8bf19994464.pdf
- https://cdn.shopify.com/s/files/1/0432/1578/2048/files/60027516271.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f871d7f72b39.pdf
- https://cdn-cms.f-static.net/uploads/4413370/normal_5f9879c35c253.pdf
- https://cdn-cms.f-static.net/uploads/4376602/normal_5f8e5b547c3e4.pdf
- https://cdn-cms.f-static.net/uploads/4380380/normal_5f995f8fda1a3.pdf
- https://cdn-cms.f-static.net/uploads/4386074/normal_5f9269b552038.pdf
- https://cdn.shopify.com/s/files/1/0485/0876/4321/files/coleman_3_person_tent_dimensions.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report