SUSPICIOUS — 2128372.pdf
SUSPICIOUS — 2128372.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b37747eb5ca36b7aab5447a112b67d0e7fc5ba8a8fa9a7bc76919169f4754ef1 - SHA-1:
a0effbec3c904a4e6b66e1d4662b2c77cb2d9ddc - MD5:
eb43e3e4f61feee2129476f4b791dc21 - ssdeep:
1536:7GFeyQMmPIZfJZCbRfjAXaSV3ZkglbfZ4gVrptQ:aFeyiPoqbyaSVpZVR4crA - TLSH:
T135349FF34057ED887E8BBB176DF71999518AD78970329A70488CB72CC07C2BE5E40591 - Submitted as: 2128372.pdf
- File type: pdf · Size: 53330 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20unheavenly%20city%20revisited%20pdf, https://uploads.strikinglycdn.com/files/934b93ee-578c-4793-a965-cb494208e015/nilowezarovibe.pdf, https://cdn.shopify.com/s/files/1/0478/2758/3135/files/helden_wie_wir.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20unheavenly%20city%20revisited%20pdf
- https://uploads.strikinglycdn.com/files/934b93ee-578c-4793-a965-cb494208e015/nilowezarovibe.pdf
- https://cdn.shopify.com/s/files/1/0478/2758/3135/files/helden_wie_wir.pdf
- https://uploads.strikinglycdn.com/files/f39cacac-6f6f-4cd1-a142-1fdbf7a86f20/dream_house_a_novel_by_cutiepiemarzia.pdf
- https://cdn.shopify.com/s/files/1/0434/3939/0872/files/define_fragment_in_android.pdf
- https://uploads.strikinglycdn.com/files/1d5c13a0-1b39-454d-a44f-3fd5a1c8612a/95479698783.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f8c98e949f7e.pdf
- https://uploads.strikinglycdn.com/files/898bbf22-a41e-4982-a8fb-a86fd6b00cbc/vidarixelopajaxovixamunu.pdf
- https://uploads.strikinglycdn.com/files/2d99dc3d-ea56-44db-af12-6ea011d77c2c/70949713268.pdf
- https://cdn.shopify.com/s/files/1/0498/2698/8194/files/67456647733.pdf
- https://s3.amazonaws.com/gewuwasi/fizomefurusevazower.pdf
- https://uploads.strikinglycdn.com/files/9eee6991-361f-4489-96fd-0d7f7a7a8b9f/14357708572.pdf
- https://uploads.strikinglycdn.com/files/9b2f9f57-8c67-46ad-b1e8-62a98d629fec/96275060708.pdf
- https://s3.amazonaws.com/fosagoba/control_of_airborne_diseases.pdf
- https://uploads.strikinglycdn.com/files/7c29bc7c-f87a-4511-9629-1dde84b82134/siniwivaliluxilujet.pdf
- https://cdn-cms.f-static.net/uploads/4415530/normal_5f9a25b6f38c1.pdf
- https://cdn.shopify.com/s/files/1/0468/8606/0189/files/25300739337.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report