SUSPICIOUS — 7417aa454242.pdf
SUSPICIOUS — 7417aa454242.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
cdec8a8a75a0fafef286ec764f9984dea214ba96f64bd18540956af99e71e1da - SHA-1:
01c5d427b8ef0ff4f8915fd35973c54d06df9ce6 - MD5:
88de2a994f0bf94d40e848c54866fa32 - ssdeep:
768:egGzpDHyxxJwRhhyR1XNRdbTPPLd3uLzqx0F9xVwTvzw5OdR+5Z+dj:bGFzoxJOej3dBue0rwPwK+58j - TLSH:
T16032AFF3A067ED8C6A87AF132D65119EA095D68D6033A76408D87F7CC4BD6BC2E01960 - Submitted as: 7417aa454242.pdf
- File type: pdf · Size: 46186 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=aiea%20intermediate%20school%20schedule, https://cdn-cms.f-static.net/uploads/4365549/normal_5f87339d5b685.pdf, https://jewajufigojoxi.weebly.com/uploads/1/3/1/4/131438211/pufatigenajilobow.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=aiea%20intermediate%20school%20schedule
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f87339d5b685.pdf
- https://jewajufigojoxi.weebly.com/uploads/1/3/1/4/131438211/pufatigenajilobow.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/f22a81f.pdf
- https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/nejuvamexuxa.pdf
- https://fakimodixoto.weebly.com/uploads/1/3/0/7/130739088/sowajagilemokaj_sebuzewij_jolepobisi.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/e52a51a4.pdf
- https://tenanetudoji.weebly.com/uploads/1/3/4/2/134266315/5037106.pdf
- https://kufazijofiw.weebly.com/uploads/1/3/0/7/130776126/3440839.pdf
- https://cdn.shopify.com/s/files/1/0498/8603/6142/files/download_vpn_for_android_4.0.4.pdf
- https://pevinuwipe.weebly.com/uploads/1/3/0/8/130873962/8960134.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/movew.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f880c0b93329.pdf
- https://loponulofaxoli.weebly.com/uploads/1/3/4/3/134324484/kugig_dolegeligaserif_dutinaputilexi_sejus.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- jewajufigojoxi.weebly.com
- wetuxabo.weebly.com
- wosezobar.weebly.com
- fakimodixoto.weebly.com
- xumogimunosu.weebly.com
- tenanetudoji.weebly.com
- kufazijofiw.weebly.com
- cdn.shopify.com
- pevinuwipe.weebly.com
- jatorogerujew.weebly.com
- loponulofaxoli.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report