SUSPICIOUS — 8c72c2e2ea81.pdf
SUSPICIOUS — 8c72c2e2ea81.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b9401e2b7d46b29ce3e561cf4a761a2f747e431389d746e2ce3a0040a44265ab - SHA-1:
ecc5ee116cf15b188f4bfb9fef0f6c512fccbc7f - MD5:
8e866dd93e0b9fab049781b6dea929a4 - ssdeep:
768:4gGzpDhp85M5YSdZUPyFILteWl1a0R/1Bm1zGrfoNRTELfWpR6fia5C:VGF9p80LUKSLtXn9mQLovELOpR8iak - TLSH:
T1DA339EF34057EC4C7ACBAB43AEEA2458908AD34CA13297B4949C672DC5BC2BD3F40560 - Submitted as: 8c72c2e2ea81.pdf
- File type: pdf · Size: 47662 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=leo%20construyo%20y%20escribo, https://uploads.strikinglycdn.com/files/6a655a84-6f72-41bd-af7e-b3e5070effc8/daxuvekanubobogabenawem.pdf, https://uploads.strikinglycdn.com/files/2041879e-1ece-4873-977b-d3f15a1161ec/81280044036.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=leo%20construyo%20y%20escribo
- https://uploads.strikinglycdn.com/files/6a655a84-6f72-41bd-af7e-b3e5070effc8/daxuvekanubobogabenawem.pdf
- https://uploads.strikinglycdn.com/files/2041879e-1ece-4873-977b-d3f15a1161ec/81280044036.pdf
- https://uploads.strikinglycdn.com/files/a7300930-7315-4ce8-91b1-6c56296c5a4d/90396584824.pdf
- https://uploads.strikinglycdn.com/files/4846ad08-b801-488f-9d1b-c50744740029/61792538165.pdf
- https://uploads.strikinglycdn.com/files/e4e28c1d-77d6-4e6a-bed5-6d22adb7bc7f/77538032692.pdf
- https://site-1043032.mozfiles.com/files/1043032/97393538826.pdf
- https://site-1040175.mozfiles.com/files/1040175/33476719189.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f86f47ccc754.pdf
- https://cdn-cms.f-static.net/uploads/4370560/normal_5f88c2dee193a.pdf
- https://site-1039898.mozfiles.com/files/1039898/75110421977.pdf
- https://site-1038820.mozfiles.com/files/1038820/dikuru.pdf
- https://site-1038765.mozfiles.com/files/1038765/rekezatubopijapudibosax.pdf
- https://site-1039152.mozfiles.com/files/1039152/risusu.pdf
- https://site-1045368.mozfiles.com/files/1045368/2150996481.pdf
- https://site-1039578.mozfiles.com/files/1039578/12751592311.pdf
- https://uploads.strikinglycdn.com/files/3867ef10-cdb0-4709-9341-96b82294c8d3/fiwavasoduvepefipafakig.pdf
- https://uploads.strikinglycdn.com/files/4b440205-a575-4dbe-a9d8-233c3df73a8a/mutemunonitobanexujevuni.pdf
- https://uploads.strikinglycdn.com/files/a021ff98-a240-4637-8bf5-6e5a182ccd50/xasel.pdf
- https://uploads.strikinglycdn.com/files/1ae1da55-b0df-41e1-a136-1ae5aa44a0ea/78922573209.pdf
- https://uploads.strikinglycdn.com/files/2e5f69ca-81ce-4d2c-a8b0-8d361832405c/54775928740.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1043032.mozfiles.com
- site-1040175.mozfiles.com
- cdn-cms.f-static.net
- site-1039898.mozfiles.com
- site-1038820.mozfiles.com
- site-1038765.mozfiles.com
- site-1039152.mozfiles.com
- site-1045368.mozfiles.com
- site-1039578.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report