SUSPICIOUS — 1042999.pdf
SUSPICIOUS — 1042999.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
baf8da147d45a12f2f5dc4c929c2ec0bfbe39f3644ae73168bbf5281c455cc93 - SHA-1:
152d3fe5e7b01520540741f5010aa6c3860e2ed1 - MD5:
b8cfebfe6d3dd505ced6f67b933cd33f - ssdeep:
768:IgGzpDgYrCDI7m/smRca6uwHebLdUhiVyatZyW/bcz10Fr:FGFMYrcCatwHeFvyaPyWQh0Fr - TLSH:
T1252F7CF310A7EC8C7A87EF135EBA5559A18EC64C713296A045C8372CD4BC6BD6F108A1 - Submitted as: 1042999.pdf
- File type: pdf · Size: 35246 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=troutman%20variational%20calculus%20and%20optimal%20control%20pdf, https://cdn-cms.f-static.net/uploads/4375361/normal_5f8b36cc261fa.pdf, https://uploads.strikinglycdn.com/files/0349e344-c1ac-4fc4-99e9-3626dc73a3f8/foliguwujeri.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=troutman%20variational%20calculus%20and%20optimal%20control%20pdf
- https://cdn-cms.f-static.net/uploads/4375361/normal_5f8b36cc261fa.pdf
- https://uploads.strikinglycdn.com/files/0349e344-c1ac-4fc4-99e9-3626dc73a3f8/foliguwujeri.pdf
- https://cdn-cms.f-static.net/uploads/4417669/normal_5f9975d27ee86.pdf
- https://cdn-cms.f-static.net/uploads/4410415/normal_5f9b3338db54d.pdf
- https://uploads.strikinglycdn.com/files/cfb22deb-1c15-4f13-888c-deb360c44ed2/20358280138.pdf
- https://s3.amazonaws.com/tonemakopinibem/persona_3_strength_flag.pdf
- https://uploads.strikinglycdn.com/files/01322261-d935-4699-beaa-f13620070fca/sevalusixumibejovobur.pdf
- https://uploads.strikinglycdn.com/files/26e3d09e-7d7a-4fd2-bbae-f3bb582b9703/diccionario_etimologico_biblico.pdf
- https://uploads.strikinglycdn.com/files/2e10d51f-f339-45f6-ae63-dab05c3a976f/lozebajegarinakito.pdf
- https://uploads.strikinglycdn.com/files/79854810-8b12-4b14-8b5b-862609d07cf9/95370666137.pdf
- https://cdn-cms.f-static.net/uploads/4366325/normal_5f8d6eb6b4485.pdf
- https://uploads.strikinglycdn.com/files/7bde70a9-2949-41d2-a792-446c58b1b30b/4.2_estrategias_basicas_del_sistema_jit.pdf
- https://s3.amazonaws.com/wixamupelinere/40090081109.pdf
- https://s3.amazonaws.com/zosevid/jilubizedemazatej.pdf
- https://s3.amazonaws.com/gorajikunobixi/plazmaburst2_official_website.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- iucr.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report