SUSPICIOUS — 49295045760.pdf
SUSPICIOUS — 49295045760.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
d50b410de19d8386f19c5b683384cc48635d8bb09f9cb8e3e567b7451b4cd823 - SHA-1:
2125494b9138cebb3c5957b60a3354a613cd97cb - MD5:
588d2676115ae1fab716954601c40cfc - ssdeep:
1536:JGF4AUAI1q7rZWPn53kD9FZt6f7wVcnILDrNMC:cF4Zx2gB0D9FZt6DwCnILHP - TLSH:
T12C33BFF34053ED8C7A576B03AEE601496189C7853132DAA458AC7A7CD07CBFCBD44A62 - Submitted as: 49295045760.pdf
- File type: pdf · Size: 50038 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=scooby+doo+mystery+incorporated+full+episodes+dailymotion+season+1, https://cdn.shopify.com/s/files/1/0438/3768/5920/files/timutu.pdf, https://cdn.shopify.com/s/files/1/0435/8832/1435/files/farmers_lab_seeds_reddit.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=scooby+doo+mystery+incorporated+full+episodes+dailymotion+season+1
- https://cdn.shopify.com/s/files/1/0438/3768/5920/files/timutu.pdf
- https://cdn.shopify.com/s/files/1/0435/8832/1435/files/farmers_lab_seeds_reddit.pdf
- https://cdn.shopify.com/s/files/1/0438/6213/0848/files/4553441359.pdf
- https://cdn.shopify.com/s/files/1/0482/7506/2945/files/62036604647.pdf
- https://cdn.shopify.com/s/files/1/0476/9090/7814/files/fulumisiluv.pdf
- https://uploads.strikinglycdn.com/files/7a897ffc-d097-49cd-8e8b-73f02513db92/43927371725.pdf
- https://uploads.strikinglycdn.com/files/3ba33b97-3959-4f28-9b50-f3c521245bd0/lipewulokepufeb.pdf
- https://uploads.strikinglycdn.com/files/dfb6df89-55d9-41e7-a1ee-80a9001bbfee/18812964009.pdf
- https://uploads.strikinglycdn.com/files/ba61bfce-1dc9-40e0-a8c4-a328f3cd714e/11067126696.pdf
- https://uploads.strikinglycdn.com/files/757a7f1a-61a6-48a4-ab21-158187b68c0f/gonajerupumela.pdf
- https://uploads.strikinglycdn.com/files/21b51135-32c0-4c15-af0c-cff662655818/38777338812.pdf
- https://uploads.strikinglycdn.com/files/e2527fc2-8ccc-4018-b821-fb82aec88f9f/gudidido.pdf
- https://uploads.strikinglycdn.com/files/cdf26ebe-6837-452e-91d1-c4be10af0a98/novujusawigijisokoj.pdf
- https://uploads.strikinglycdn.com/files/5359b280-7890-42e8-a66a-03a5cec19371/kunabowir.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report