SUSPICIOUS — 6742352.pdf
SUSPICIOUS — 6742352.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
bdaaedd106864058770bdd352e2a9c4a48eb3b096351b703f7937243ca000f1e - SHA-1:
72b8d2f9b0e015a165a7c7de02dcb81087bc1854 - MD5:
7a59b48268e695767ebc0a25e02ed268 - ssdeep:
768:QgGzpDkpv2rxfq5rrBd3SErfK33UCiX7t9Qj/Ax0q4ewK:9GFwp/d3SErfKUdp9QbO0xewK - TLSH:
T157329DF3549BDD8CBA8AEB03ADB71459548AD38C6137E360549CB72DC4B82BC7E00961 - Submitted as: 6742352.pdf
- File type: pdf · Size: 45099 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=sparkle%20city%20comics, https://sesorefamasupuv.weebly.com/uploads/1/3/1/0/131071262/9179173.pdf, https://varipejat.weebly.com/uploads/1/3/0/7/130739080/simaw_witedopisof_loludujebuke_mojota.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=sparkle%20city%20comics
- https://sesorefamasupuv.weebly.com/uploads/1/3/1/0/131071262/9179173.pdf
- https://varipejat.weebly.com/uploads/1/3/0/7/130739080/simaw_witedopisof_loludujebuke_mojota.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/fubumimig.pdf
- https://cdn.shopify.com/s/files/1/0434/9231/1206/files/49784299482.pdf
- https://cdn.shopify.com/s/files/1/0482/6179/1905/files/83589056205.pdf
- https://uploads.strikinglycdn.com/files/32a63ce0-ffdb-4129-9295-443eeb16046e/67305464675.pdf
- https://uploads.strikinglycdn.com/files/002c04fa-332a-4dc0-b2b8-a4972ef006e0/25560141975.pdf
- https://uploads.strikinglycdn.com/files/4b50502f-4fc6-41e9-96fa-e5dc347e4e94/75094828861.pdf
- https://uploads.strikinglycdn.com/files/3586dc7a-9ed9-44b8-9211-9fde4b1fca65/tewebiviwov.pdf
- https://uploads.strikinglycdn.com/files/085d07d8-461c-4cdb-b33e-345eca99bb79/71319341713.pdf
- https://uploads.strikinglycdn.com/files/a12d3b4e-05d6-45a8-8997-9e8486008e85/96468098752.pdf
- https://uploads.strikinglycdn.com/files/5b5ea5b7-981c-4997-bd36-dc2b4b95f689/12942505134.pdf
- https://uploads.strikinglycdn.com/files/0170a89e-6e1f-45ed-92e8-ffdb8efafc42/80933146318.pdf
- https://uploads.strikinglycdn.com/files/9df90495-03ce-4cd6-b1d2-688d06712c9a/32228127625.pdf
- https://uploads.strikinglycdn.com/files/ad7da9d7-7989-4544-a3c7-0694ace160ea/lotekokosow.pdf
- https://uploads.strikinglycdn.com/files/525945e1-0b36-413e-a77a-29a25b0fd48b/74234345313.pdf
- https://uploads.strikinglycdn.com/files/ea1cc06e-12f0-491d-bb6a-69d6e30f7e18/jufoxujilawaguwaxevukij.pdf
- https://uploads.strikinglycdn.com/files/1029ce69-1340-4917-844b-771e078348dc/3636268263.pdf
- https://uploads.strikinglycdn.com/files/d3139ec4-3a26-499d-ad32-02015d1a536f/62955384727.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- sesorefamasupuv.weebly.com
- varipejat.weebly.com
- xazapadikud.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report