SUSPICIOUS — 7701cd8.pdf
SUSPICIOUS — 7701cd8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a370e4c16885b125ed779081c0570b0207f6836fc8ac47525f763309aa85fa9c - SHA-1:
5973ce667adf810986db6e6f2437d1a3d00568ee - MD5:
7586789c5e6be1e529838bceccc92ee5 - ssdeep:
768:zgGzpDxWSAgPVppa1U1Ds9idUPszWvkfWFkLCYLp+t+sB1K3SrGBdZ/:MGFVBdL0FkWy+tZB1K3S6BdZ/ - TLSH:
T1B1319EF36063DE4C79879F13ADBB149D218AD78C6132A260048C7BACC5BC6BD6E51871 - Submitted as: 7701cd8.pdf
- File type: pdf · Size: 42169 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=manuale%20d, https://cdn.shopify.com/s/files/1/0499/8440/5667/files/62678029411.pdf, https://cdn.shopify.com/s/files/1/0485/0607/7339/files/trafico_y_transporte_santa_cruz_bolivia.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=manuale%20d
- https://cdn.shopify.com/s/files/1/0499/8440/5667/files/62678029411.pdf
- https://s3.amazonaws.com/sedimeraxufi/30288449775.pdf
- https://s3.amazonaws.com/regegozumekoza/64645510327.pdf
- https://cdn.shopify.com/s/files/1/0485/0607/7339/files/trafico_y_transporte_santa_cruz_bolivia.pdf
- https://cdn-cms.f-static.net/uploads/4387825/normal_5f8d40a3567c3.pdf
- https://cdn-cms.f-static.net/uploads/4379230/normal_5f8a51b910eb8.pdf
- https://cdn.shopify.com/s/files/1/0438/0786/7037/files/taxomazafidosawurodig.pdf
- https://cdn-cms.f-static.net/uploads/4414514/normal_5f95674016df0.pdf
- https://s3.amazonaws.com/votawawo/meditations_marcus_aurelius_gregory_hays.pdf
- https://s3.amazonaws.com/davolazupivowi/33976573940.pdf
- https://cdn.shopify.com/s/files/1/0429/5580/0739/files/42848698389.pdf
- https://cdn.shopify.com/s/files/1/0266/8386/7326/files/aggiornamento_android_oreo_huawei_p8_lite_2020.pdf
- https://cdn.shopify.com/s/files/1/0503/1087/3273/files/gatanofuj.pdf
- https://cdn-cms.f-static.net/uploads/4387424/normal_5f997a3f06279.pdf
- https://cdn-cms.f-static.net/uploads/4389104/normal_5f99de3d8e32e.pdf
- https://cdn.shopify.com/s/files/1/0496/4581/3924/files/37339154658.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report