SUSPICIOUS — 344000.pdf
SUSPICIOUS — 344000.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c0bb58da11bde0edd85fb16a461885a8fd34238412b8c04356f0a715fe65e6df - SHA-1:
1b999a948458103e04744b8060a933e9708af171 - MD5:
c48fd3e13d909383fb8eff1321fa9bdc - ssdeep:
768:OgGzpDOpK4S9UAdKy4ACNppXuvsuL7lWnFyeHgF1EHfVC+lCYlVKZ:rGFqpK96FtclWn0TPE/7lCYlVKZ - TLSH:
T186328EF750A3DC8C798AEB039EEA255D948AD7885133AB60858C372DC47C7BD3E10991 - Submitted as: 344000.pdf
- File type: pdf · Size: 44134 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=kenmore%20ultrasoft%20800, https://cdn.shopify.com/s/files/1/0477/3730/7292/files/lakonufotugadel.pdf, https://cdn.shopify.com/s/files/1/0431/4411/8434/files/ririwudukibisi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=kenmore%20ultrasoft%20800
- https://cdn.shopify.com/s/files/1/0477/3730/7292/files/lakonufotugadel.pdf
- https://cdn.shopify.com/s/files/1/0431/4411/8434/files/ririwudukibisi.pdf
- https://cdn.shopify.com/s/files/1/0434/4456/8220/files/48712904887.pdf
- https://cdn.shopify.com/s/files/1/0432/7761/5262/files/v_for_vendetta_graphic_novel_first_edition.pdf
- https://uploads.strikinglycdn.com/files/b3ad18c7-aaf6-4612-8c33-8e9210c60591/bapujenidodoku.pdf
- https://uploads.strikinglycdn.com/files/2221a279-d30c-402c-b47e-c2bb2e4c07d6/81958842011.pdf
- https://uploads.strikinglycdn.com/files/1372b568-3bda-4ed3-ac38-0bbcf5d10618/viwajo.pdf
- https://uploads.strikinglycdn.com/files/a6343189-eb5b-4d81-b570-82fb83b68beb/26344639525.pdf
- https://uploads.strikinglycdn.com/files/aa4dc2e2-49e5-4788-adb1-d0048bee8f83/wulevufabusese.pdf
- https://uploads.strikinglycdn.com/files/b5c27610-eb06-46ac-a618-aba35a075b1d/kodikugevotisatedo.pdf
- https://uploads.strikinglycdn.com/files/15e82a4b-937f-4d8f-8a99-c42e0c545300/41012277896.pdf
- https://uploads.strikinglycdn.com/files/30c35d62-162a-4faa-bae7-95f6311f44fe/xisudesuvijutenobepibune.pdf
- https://uploads.strikinglycdn.com/files/8685a327-2b1e-49af-84fd-a2f6818a296a/penejotobulugi.pdf
- https://uploads.strikinglycdn.com/files/7b914f12-2ca1-47d2-a9c8-8b2d79e03dfe/vaxobowoporipegazadi.pdf
- https://uploads.strikinglycdn.com/files/5a4fa545-2249-424d-8b32-1c8606b3cb07/guwabagiv.pdf
- https://cdn-cms.f-static.net/uploads/4369343/normal_5f87bce0924bb.pdf
- https://cdn-cms.f-static.net/uploads/4368266/normal_5f87f6e7a5c79.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f86f4001a788.pdf
- https://site-1048200.mozfiles.com/files/1048200/83721563578.pdf
- https://site-1038338.mozfiles.com/files/1038338/kodugazowupowaxozamepefik.pdf
- https://site-1045415.mozfiles.com/files/1045415/mosabuzapasineroribem.pdf
- https://site-1039923.mozfiles.com/files/1039923/84996516749.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1048200.mozfiles.com
- site-1038338.mozfiles.com
- site-1045415.mozfiles.com
- site-1039923.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report