SUSPICIOUS — 3939665.pdf
SUSPICIOUS — 3939665.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ab3877d85acda4b67d1d41a6e69588140bd1531c5e677b3b7870ec55d531112d - SHA-1:
048fe6bc5650713c8ef8e7e498164196ad1b0932 - MD5:
dcee0a5e3a37043c7953ef1fa74083b8 - ssdeep:
768:dgGzpDkeQ6LI93nClEO6gpnNZ1tPU3vj3DVRbdOqV7KbC85kwWJyi23:eGFIeQ2LnN5S/DYqV7KbW8i23 - TLSH:
T151339EF710A7EC8C7787AF039DBB2569648EC78861369760448C376EC1BC2BD6E10961 - Submitted as: 3939665.pdf
- File type: pdf · Size: 51394 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=transdermal%20drug%20delivery%20system%20ppt%20pdf, https://uploads.strikinglycdn.com/files/fe88b334-0bea-4e03-9e94-0941e915cdff/80681480844.pdf, https://uploads.strikinglycdn.com/files/b9a6d3a2-f691-41b5-8dff-dac329bd6595/26258522457.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=transdermal%20drug%20delivery%20system%20ppt%20pdf
- https://uploads.strikinglycdn.com/files/fe88b334-0bea-4e03-9e94-0941e915cdff/80681480844.pdf
- https://uploads.strikinglycdn.com/files/b9a6d3a2-f691-41b5-8dff-dac329bd6595/26258522457.pdf
- https://uploads.strikinglycdn.com/files/673e1f73-b234-4d56-8b4b-185289b6437c/37341656085.pdf
- https://s3.amazonaws.com/magapeguwabe/gawixepigutadufikonilixu.pdf
- https://s3.amazonaws.com/moduxanakuri/medicina_ancestral_y_epigenetica_libro.pdf
- https://s3.amazonaws.com/lanorolowu/barron_s_toeic_5th_edition.pdf
- https://cdn-cms.f-static.net/uploads/4391649/normal_5f95fa69ecde1.pdf
- https://cdn-cms.f-static.net/uploads/4373271/normal_5f8d2d30bc909.pdf
- https://cdn-cms.f-static.net/uploads/4392651/normal_5f9599722c537.pdf
- https://cdn.shopify.com/s/files/1/0496/5325/2259/files/gitepuxefitukinemuzo.pdf
- https://cdn.shopify.com/s/files/1/0430/4502/7993/files/tarazizomujokixelukumo.pdf
- https://cdn.shopify.com/s/files/1/0482/6988/5601/files/101_inventions_that_changed_the_world.pdf
- https://uploads.strikinglycdn.com/files/ded4befd-031d-46e2-ad27-394a579f08c2/leneruwajawo.pdf
- https://uploads.strikinglycdn.com/files/7ce0877e-a005-4223-8b48-15a39c080273/72161250404.pdf
- https://uploads.strikinglycdn.com/files/a85c51d6-232e-455b-8ea1-1fcd3403d751/xuwolixuri.pdf
- https://uploads.strikinglycdn.com/files/2ca14a45-cc9a-4a9d-8920-baba98ccc171/potebijoxupinut.pdf
- https://uploads.strikinglycdn.com/files/d91a1dad-6c5e-42a0-b31c-e1fe03fd9375/wadute.pdf
- https://uploads.strikinglycdn.com/files/6f12c28c-b365-409a-8c2d-a495975f6aff/66453640877.pdf
- https://uploads.strikinglycdn.com/files/04bf0aef-11e0-48d4-a081-2bc0606b8651/94948110611.pdf
- https://uploads.strikinglycdn.com/files/3f5d3e44-a872-49cf-9a0f-6e5b1926cc55/97121435180.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report