SUSPICIOUS — 1486329.pdf
SUSPICIOUS — 1486329.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
ce5bacf6cfc866d6bb293eaaa00f0ebde3d617a2b656aa3c38569093949f9195 - SHA-1:
ab3c4c27cf94266c66b0d110f8ebb01f85267a1f - MD5:
10c4628292e8e8efc7e54cfffffdf2ec - ssdeep:
1536:ZGF8pN9uuDSmG9AJrDNW6khNoFXc5bBsCWgFsJ71Ch:sF8pNjdG9eN6hCFXcbCF5W - TLSH:
T1D0349DF35097DD8D7E86AF03A8AB10A9A18AD74C2136D7A05588B72CC4BC5FCBF50950 - Submitted as: 1486329.pdf
- File type: pdf · Size: 55777 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pretty%20female%20idles%20sse, https://cdn-cms.f-static.net/uploads/4367273/normal_5f8f7a729f2ce.pdf, https://cdn-cms.f-static.net/uploads/4377642/normal_5f8b942ea4f49.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pretty%20female%20idles%20sse
- https://cdn-cms.f-static.net/uploads/4367273/normal_5f8f7a729f2ce.pdf
- https://cdn-cms.f-static.net/uploads/4377642/normal_5f8b942ea4f49.pdf
- https://cdn-cms.f-static.net/uploads/4376374/normal_5f8bf58fc13b5.pdf
- https://cdn-cms.f-static.net/uploads/4373986/normal_5f8f6a8134069.pdf
- https://uploads.strikinglycdn.com/files/ad0207ef-e5d6-4c42-b114-3b6c5f4dfea3/beginners_guide_to_wicca.pdf
- https://uploads.strikinglycdn.com/files/400b6749-6fba-4214-9bd9-83a96f74e507/80325698630.pdf
- https://uploads.strikinglycdn.com/files/0832a8d6-bedb-44c0-b422-ef2815bf390c/gijonapuvomezowulofetoxej.pdf
- https://uploads.strikinglycdn.com/files/04e89f86-c622-49d2-83d3-4dad5674f6a6/jemenope.pdf
- https://uploads.strikinglycdn.com/files/9655729c-ed8b-4d0a-8a09-753f0f9aca98/83388160339.pdf
- https://cdn-cms.f-static.net/uploads/4373505/normal_5f8bf16ee7a45.pdf
- https://cdn-cms.f-static.net/uploads/4382627/normal_5f8dd09737c12.pdf
- https://cdn-cms.f-static.net/uploads/4367627/normal_5f8d07aa8bf4a.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f8e059b14307.pdf
- https://cdn-cms.f-static.net/uploads/4387931/normal_5f8d55846c50a.pdf
- https://cdn.shopify.com/s/files/1/0496/2644/8023/files/bill_of_rights_worksheet_middle_school.pdf
- https://cdn.shopify.com/s/files/1/0432/3357/5075/files/gigagatomazefojowuvukuv.pdf
- https://cdn.shopify.com/s/files/1/0434/5289/1297/files/southwest_asia_map_rivers.pdf
- https://cdn.shopify.com/s/files/1/0434/9493/2640/files/rules_of_exponents_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0485/0650/3323/files/pizofetotixulokata.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f874c4c24413.pdf
- https://cdn-cms.f-static.net/uploads/4372960/normal_5f8c7e3c7e128.pdf
- https://cdn-cms.f-static.net/uploads/4379474/normal_5f8e7c1393dce.pdf
- https://s3.amazonaws.com/fasanag/mevusixixuruf.pdf
- https://s3.amazonaws.com/wilugugo/cantaloupe_island_trumpet_solo_transcription.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report