SUSPICIOUS — 92858030682.pdf
SUSPICIOUS — 92858030682.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
bb521a0cacaf170f698f05143bca4848788775e0e71ddbe504cab6ed6c7d3ae3 - SHA-1:
6531a23ef1ae153a8289936f664e9fda4c7a3f7f - MD5:
d9735045382138edcc7a6e834ab11bec - ssdeep:
768:KgGzpDvuIZGu4W2iDb9BPhn68Rla4BsaFoSLLe/ZUyM6IMdBdQ66Lpbac36Vm:XGFLVZlP7OyLeRpBFnSnbac36Vm - TLSH:
T18B319DF31067DD8C6BCE9B07ADB71158A145C34D7032D7605498BA2CD87CAFDAE10A21 - Submitted as: 92858030682.pdf
- File type: pdf · Size: 42432 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=ucf+writing+center+resources, https://uploads.strikinglycdn.com/files/d9db0405-d9dc-4b41-ba88-021534f5a1be/kemalaxabu.pdf, https://uploads.strikinglycdn.com/files/ae0debba-e754-4009-891f-e46b21ce5b6d/tibevami.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=ucf+writing+center+resources
- https://uploads.strikinglycdn.com/files/d9db0405-d9dc-4b41-ba88-021534f5a1be/kemalaxabu.pdf
- https://uploads.strikinglycdn.com/files/ae0debba-e754-4009-891f-e46b21ce5b6d/tibevami.pdf
- https://uploads.strikinglycdn.com/files/57a2bb99-41b2-4029-a82c-d4f0ca361165/zumavuxixifaluxefaviro.pdf
- https://uploads.strikinglycdn.com/files/293d3fe2-7c3c-4caa-9ef7-fd8075e0ff53/60003078168.pdf
- https://cdn.shopify.com/s/files/1/0428/7699/3702/files/dieta_y_ejercicio_para_marcar_abdomen_mujer.pdf
- https://cdn.shopify.com/s/files/1/0433/9816/8743/files/lago_de_yojoa_contaminacion.pdf
- https://cdn.shopify.com/s/files/1/0431/1213/6855/files/cdl_manual_florida_en_espanol.pdf
- https://cdn.shopify.com/s/files/1/0481/5693/4297/files/69991447435.pdf
- https://cdn.shopify.com/s/files/1/0430/9683/4212/files/chemistry_1_predicting_products_worksheet.pdf
- https://site-1041501.mozfiles.com/files/1041501/99693803163.pdf
- https://site-1036737.mozfiles.com/files/1036737/zadaluzaxejovonazoj.pdf
- https://site-1040203.mozfiles.com/files/1040203/nolajigisofudetunone.pdf
- https://site-1038861.mozfiles.com/files/1038861/jinis.pdf
- https://site-1039279.mozfiles.com/files/1039279/juxegulenifineletemawis.pdf
- https://uploads.strikinglycdn.com/files/ca11be39-0f0d-4735-a6eb-b8f5076ae430/nawizepuvevifejobebugozar.pdf
- https://uploads.strikinglycdn.com/files/f5abe5fc-4631-47a6-a838-67f3b7d83941/dajorogoniro.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1041501.mozfiles.com
- site-1036737.mozfiles.com
- site-1040203.mozfiles.com
- site-1038861.mozfiles.com
- site-1039279.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report