SUSPICIOUS — c444a24881c061.pdf
SUSPICIOUS — c444a24881c061.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d5e6e5342a87774cce2ef1c87febd58f0d3821656fe3710074325034f1b474a1 - SHA-1:
0e2f22c2cc8b133ea928d6f1a9515df666bd6dd8 - MD5:
5685e8f8c8733ca18ea20e1e9f641a39 - ssdeep:
768:jgGzpDgpaadlB2/kDdZUsYGP1JZnwuDCA7dJtvkWfBvUr1VGJB74/fbPxuQftI:cGFMpR7DTNfB8r1VyebZ5ftI - TLSH:
T1EE328EF360A3DD0D7A8A9F13ADBB1569204EC788B036DB6054CC762DD47C6AE7E50860 - Submitted as: c444a24881c061.pdf
- File type: pdf · Size: 46528 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=best%20talisman%20god%20of%20war, https://cdn-cms.f-static.net/uploads/4368485/normal_5f87f86fc8b91.pdf, https://cdn-cms.f-static.net/uploads/4367281/normal_5f874b7940002.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=best%20talisman%20god%20of%20war
- https://cdn-cms.f-static.net/uploads/4368485/normal_5f87f86fc8b91.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f874b7940002.pdf
- https://cdn-cms.f-static.net/uploads/4368999/normal_5f87b1ec2635c.pdf
- https://cdn-cms.f-static.net/uploads/4369901/normal_5f87f1003182b.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f8732d2a0770.pdf
- https://uploads.strikinglycdn.com/files/e0c6399d-d4c3-4f77-af7f-4d5166c2aee3/wemerupexikoduf.pdf
- https://uploads.strikinglycdn.com/files/51d80ffb-d598-4c4e-9a2e-b23fd7bd01cf/34753826946.pdf
- https://uploads.strikinglycdn.com/files/e3c78a1e-863b-41df-ab91-73eaa7f37bcb/punujixuwuxanutegeras.pdf
- https://site-1043218.mozfiles.com/files/1043218/xotel.pdf
- https://site-1039933.mozfiles.com/files/1039933/zijarisetime.pdf
- https://site-1044067.mozfiles.com/files/1044067/87954073540.pdf
- https://site-1043696.mozfiles.com/files/1043696/96732763387.pdf
- https://lajojixuvoporor.weebly.com/uploads/1/3/0/7/130738555/dd67ae3f5bfe83d.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/golosumixo.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kadupe_ripovu_jozovagazemewe.pdf
- https://cdn.shopify.com/s/files/1/0484/2402/6262/files/el_paso_county_clerk_and_recorder_search.pdf
- https://cdn.shopify.com/s/files/1/0434/6321/3209/files/veritas_mk_ii_honing_guide_set.pdf
- https://cdn.shopify.com/s/files/1/0495/4600/2584/files/saxesij.pdf
- https://cdn.shopify.com/s/files/1/0478/0710/3143/files/pirate_bays_proxy_2020_reddit.pdf
- https://cdn.shopify.com/s/files/1/0498/7607/4654/files/27073223268.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f873ea22f0f6.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f86f9188dda8.pdf
- https://cdn-cms.f-static.net/uploads/4367624/normal_5f876a0fe5d1a.pdf
- https://cdn-cms.f-static.net/uploads/4367312/normal_5f87ac6abb932.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1043218.mozfiles.com
- site-1039933.mozfiles.com
- site-1044067.mozfiles.com
- site-1043696.mozfiles.com
- lajojixuvoporor.weebly.com
- loguxofe.weebly.com
- gimejexoxixaza.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report