SUSPICIOUS — 7183795.pdf
SUSPICIOUS — 7183795.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
beba91401cadde3b8222d4b7267e49689f96337efba895744e1f6ee49e69d2fe - SHA-1:
41fbb409e6da71782591b0671fbb7256e8922033 - MD5:
8b2d15758743a5da5ab8f3131c30ac72 - ssdeep:
768:ggGzpDHpWXWGPvZ691/Ybvxywe1OcEYsNXk3dzTMLnkRPnF50w2dAwozdjViHJn:tGFTpfsNX4JMz2PF508dhiHJn - TLSH:
T108329EF30097EC8DBB8BEF03ADAB106A6549D3886136D7A044DC672CD57C6AE7E40851 - Submitted as: 7183795.pdf
- File type: pdf · Size: 43962 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=stephen%20king%20the%20body%20quotes, https://cdn-cms.f-static.net/uploads/4367296/normal_5f8ab4c254618.pdf, https://cdn-cms.f-static.net/uploads/4378175/normal_5f8dbb43bed1d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=stephen%20king%20the%20body%20quotes
- https://cdn-cms.f-static.net/uploads/4367296/normal_5f8ab4c254618.pdf
- https://cdn-cms.f-static.net/uploads/4378175/normal_5f8dbb43bed1d.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f8b8600b000b.pdf
- https://cdn-cms.f-static.net/uploads/4368485/normal_5f87e77c606af.pdf
- https://cdn-cms.f-static.net/uploads/4374857/normal_5f8ac47565ea7.pdf
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f8a25c40ce5c.pdf
- https://cdn.shopify.com/s/files/1/0434/4283/1522/files/26745472938.pdf
- https://cdn.shopify.com/s/files/1/0436/9301/5195/files/bopijodaxonopavuwijolebud.pdf
- https://cdn.shopify.com/s/files/1/0481/3514/3575/files/dihybrid_problems_worksheet_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0501/1098/8442/files/visedaxeravatutedem.pdf
- https://uploads.strikinglycdn.com/files/ac0e22b7-15ac-4e61-b64b-fd35cd372066/sobakufereful.pdf
- https://uploads.strikinglycdn.com/files/195ad5ff-b9db-49ba-8995-391f140c32a4/35260860846.pdf
- https://uploads.strikinglycdn.com/files/76893f1f-1db3-47a9-b0a2-b8368123ab21/51698635458.pdf
- https://cdn.shopify.com/s/files/1/0501/5846/9281/files/dewalt_xr_battery_charger_instructions.pdf
- https://cdn.shopify.com/s/files/1/0495/8388/2392/files/whitfield_county_schools_calendar.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/kandungan_bayam_merah.pdf
- https://cdn.shopify.com/s/files/1/0503/1185/6322/files/58943593610.pdf
- https://cdn.shopify.com/s/files/1/0495/5255/6184/files/makalah_pupuk_kompos.pdf
- https://cdn.shopify.com/s/files/1/0433/8732/2522/files/microwave_egg_omelet_maker_instructions.pdf
- https://cdn.shopify.com/s/files/1/0497/9893/8778/files/pumpkin_halloween_costume_toddler.pdf
- https://cdn.shopify.com/s/files/1/0479/2474/0252/files/62250330013.pdf
- https://cdn.shopify.com/s/files/1/0471/0462/2742/files/pixel_rpg_offline_apk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report