SUSPICIOUS — a1f59f1.pdf
SUSPICIOUS — a1f59f1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b5215c116f2c89e224c767c64b80190252594d6f1d4dbe61ca68ade3fe8d7470 - SHA-1:
681619fab94c14a07fe674c225030f95b03d1548 - MD5:
e266754895c3d028f6131482bd416794 - ssdeep:
768:MgGzpDnpUD3qSz3s7tIDFZPg7VgyEeUKHjidOwyUqacDdF6jfk3HGUhrmeg9lR+p:JGFrpu91y2CjLacDdccH4ee+nOm5 - TLSH:
T18F359EF31097ED4C7A8B6B03ADA711AE948AC78D6132A7905488771DC17CBFD6F00A51 - Submitted as: a1f59f1.pdf
- File type: pdf · Size: 59136 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=kamba%20ramayanam%20in%20tamil%20pdf, https://uploads.strikinglycdn.com/files/650965e8-bda8-46ba-a5a4-65e3f2648df1/nunumotap.pdf, https://uploads.strikinglycdn.com/files/882f822c-a86a-4666-b581-b16fa99c12ac/modujubekuwon.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=kamba%20ramayanam%20in%20tamil%20pdf
- https://uploads.strikinglycdn.com/files/650965e8-bda8-46ba-a5a4-65e3f2648df1/nunumotap.pdf
- https://uploads.strikinglycdn.com/files/882f822c-a86a-4666-b581-b16fa99c12ac/modujubekuwon.pdf
- https://uploads.strikinglycdn.com/files/9a11b834-5840-4f73-a83e-eb5029ac129f/zisagegaralikegazaximetum.pdf
- https://uploads.strikinglycdn.com/files/d6af5b12-f86c-4cab-8156-392028cbe8a9/10058746904.pdf
- https://uploads.strikinglycdn.com/files/0c5200d0-3d45-41f9-a736-28b87d4e7f26/bejuritijumudil.pdf
- https://cdn.shopify.com/s/files/1/0483/9247/0685/files/pham_nhat_vuong_son.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f877ac86c87e.pdf
- https://cdn-cms.f-static.net/uploads/4369336/normal_5f87bca3695e3.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f87b5507fa8d.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f877043ebb9a.pdf
- https://cdn-cms.f-static.net/uploads/4366366/normal_5f87394078f86.pdf
- https://uploads.strikinglycdn.com/files/e191e117-273b-4db1-8943-323218868b0b/setapexowafug.pdf
- https://uploads.strikinglycdn.com/files/b3da03d2-ce57-43ca-9b74-cf27bc79ce99/64627724480.pdf
- https://uploads.strikinglycdn.com/files/f020da08-184c-4f78-b8f3-456bfba945c1/88168434944.pdf
- https://uploads.strikinglycdn.com/files/0222b131-39cf-430b-b184-c7d1926a2a1b/47025877926.pdf
- https://uploads.strikinglycdn.com/files/e4939159-f482-48ea-a375-4f02d0697592/41210619911.pdf
- https://site-1041090.mozfiles.com/files/1041090/91883721688.pdf
- https://site-1038952.mozfiles.com/files/1038952/lajovakovab.pdf
- https://site-1044071.mozfiles.com/files/1044071/87579921194.pdf
- https://site-1043165.mozfiles.com/files/1043165/24431635008.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/6813382.pdf
- https://zukamukenipebo.weebly.com/uploads/1/3/1/3/131380388/3417775.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/1140105.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/1700446.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1041090.mozfiles.com
- site-1038952.mozfiles.com
- site-1044071.mozfiles.com
- site-1043165.mozfiles.com
- sepikupi.weebly.com
- zukamukenipebo.weebly.com
- lipowuripipu.weebly.com
- nobinetezo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report