SUSPICIOUS — 70471290895.pdf
SUSPICIOUS — 70471290895.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
af067570ef86e32df0db18d38606a10df73f65a6c80e685a22b9e167c8e7d758 - SHA-1:
64322aecf9ced96143edefa3e64826e1297f87b0 - MD5:
90e8b68d3d820914df9cfc062fdad7ee - ssdeep:
768:7gGzpDr2MozV00iEDvp3TbeP5j8xnc7AK5ihOH:EGFv2MZY1bePtbhihOH - TLSH:
T1F02F7DF350A7EE4C798BAF47BDAB10897049D28D212297600998775CC0BC6FD7F00961 - Submitted as: 70471290895.pdf
- File type: pdf · Size: 34861 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=tengo+que+hacerlo+worksheet+answers, https://cdn.shopify.com/s/files/1/0434/0904/7708/files/kusojufujazubepalu.pdf, https://cdn.shopify.com/s/files/1/0486/0968/9768/files/flobberworms_hogwarts_mystery.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=tengo+que+hacerlo+worksheet+answers
- https://cdn.shopify.com/s/files/1/0434/0904/7708/files/kusojufujazubepalu.pdf
- https://cdn.shopify.com/s/files/1/0486/0968/9768/files/flobberworms_hogwarts_mystery.pdf
- https://cdn.shopify.com/s/files/1/0432/6994/7555/files/fodavosojopaxegop.pdf
- https://site-1036639.mozfiles.com/files/1036639/taxukuvatewuxaras.pdf
- https://site-1037048.mozfiles.com/files/1037048/37232221692.pdf
- https://site-1039510.mozfiles.com/files/1039510/rilotuxobumogoraluxabi.pdf
- https://site-1038831.mozfiles.com/files/1038831/27936508564.pdf
- https://site-1036965.mozfiles.com/files/1036965/28757620605.pdf
- https://site-1036828.mozfiles.com/files/1036828/vogemapanowalakififunoxov.pdf
- https://site-1036862.mozfiles.com/files/1036862/86378951094.pdf
- https://site-1036826.mozfiles.com/files/1036826/liderisusaxosatinalezuz.pdf
- https://uploads.strikinglycdn.com/files/384c4503-20a1-4bc7-8aed-0b984588fd2d/parekefolojitosati.pdf
- https://uploads.strikinglycdn.com/files/068c94fc-1217-465b-a510-ef1739744066/puzumiwogununelegofivirow.pdf
- https://uploads.strikinglycdn.com/files/d9999b0e-24cc-4611-a4ff-bfb3e265eceb/1456870976.pdf
- https://uploads.strikinglycdn.com/files/ce0ecd80-fefb-4a6b-8451-f14e4a33600c/1631810188.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1036639.mozfiles.com
- site-1037048.mozfiles.com
- site-1039510.mozfiles.com
- site-1038831.mozfiles.com
- site-1036965.mozfiles.com
- site-1036828.mozfiles.com
- site-1036862.mozfiles.com
- site-1036826.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- www.williamwithin.com
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report