SUSPICIOUS — 557826.pdf
SUSPICIOUS — 557826.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
da264d8ed2b6778bf0dc6e1a774d0287b8788d380fc29d39aca858bbffdd1e46 - SHA-1:
741468ec02e7ff8a33101790c0459a2a23b243f2 - MD5:
0b3ac53e7142296ea34f38e10f68b4e7 - ssdeep:
768:EJgGzpDvpwF0GhP/x1GBf1+TjYhcgCkXDP7h83UAkoDnKfC:pGFjpwCuAjo52TP7e3JDKfC - TLSH:
T152328EF39093ED4C7E8BFB13ADA6009A558AC349603B87A145CC372DC5BC6EE6E11850 - Submitted as: 557826.pdf
- File type: pdf · Size: 44690 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20masks%20of%20god, https://uploads.strikinglycdn.com/files/7e0ed1cf-616d-4a5c-9f5b-b3304e48ccf6/defalunejuvusewot.pdf, https://uploads.strikinglycdn.com/files/938591b1-5aaf-4f4a-843e-fcc01cfa5b5a/tagavalalasofog.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20masks%20of%20god
- https://uploads.strikinglycdn.com/files/7e0ed1cf-616d-4a5c-9f5b-b3304e48ccf6/defalunejuvusewot.pdf
- https://uploads.strikinglycdn.com/files/938591b1-5aaf-4f4a-843e-fcc01cfa5b5a/tagavalalasofog.pdf
- https://uploads.strikinglycdn.com/files/d5cab4e0-702a-4b91-87cd-773c1f418f09/51111767890.pdf
- https://uploads.strikinglycdn.com/files/2e9a6652-3aa3-4294-bafd-0764d708cc2b/kiziwanarijekiteruzizut.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f8730688b140.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f8a06055c696.pdf
- https://cdn-cms.f-static.net/uploads/4368756/normal_5f8a7c50614bd.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f8746e885b24.pdf
- https://uploads.strikinglycdn.com/files/fcf5512b-c5d0-4279-9375-76b196daaabf/zewotitozidezunuviwogogen.pdf
- https://uploads.strikinglycdn.com/files/677758b3-5ef1-451a-9a26-b29a714d75ac/sapedukupinajabeladovu.pdf
- https://uploads.strikinglycdn.com/files/20bb7f8e-b6e1-427e-9b63-d2684d6f61b4/xuxebow.pdf
- https://uploads.strikinglycdn.com/files/eea1e1e3-2c19-484b-a719-fe5002d9d633/kijujakedavedonitalabodus.pdf
- https://uploads.strikinglycdn.com/files/1e1437ad-4f94-46cd-8f82-262c686d15a5/63840519397.pdf
- https://uploads.strikinglycdn.com/files/bea908af-ad37-4f29-947c-6e94c705914c/25351256225.pdf
- https://uploads.strikinglycdn.com/files/9b410277-e3ef-4954-b588-f1e876d54421/lutemubuzuralukajoko.pdf
- https://funiwulew.weebly.com/uploads/1/3/2/8/132814073/1872664.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/21c65.pdf
- https://uploads.strikinglycdn.com/files/cabf573e-1bb6-4077-945e-cdbf0fd27b1d/vixopefedomelidume.pdf
- https://uploads.strikinglycdn.com/files/02055abb-4ca5-4803-b464-d4d0f133a6e7/venezotub.pdf
- https://uploads.strikinglycdn.com/files/b65d5af5-fcbb-4a18-b97d-1b75ad96dc28/zosulinebujabaso.pdf
- https://uploads.strikinglycdn.com/files/8c6ed917-4d32-417a-8bcd-a9d9097a5566/39203730428.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- funiwulew.weebly.com
- xazapadikud.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report