SUSPICIOUS — e12d4ea5c9e5.pdf
SUSPICIOUS — e12d4ea5c9e5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
db8bddddde7c41147c5ae9eed42629b6f0d67422692e1384123acfb077889c33 - SHA-1:
4790961842c2f52a2c2cec2851e1925c19f685b7 - MD5:
fce677ac979407bea303a3178655df48 - ssdeep:
1536:qGFYeyPs4yacXJSGKioG5rZIwVmSfYTWYtv:TFYeKcXsG3oG5d1ESkWC - TLSH:
T149347DF31097ED4CBA87AB43AEE714AA508ED3895036D790448C772DD4BC5BC7E109A1 - Submitted as: e12d4ea5c9e5.pdf
- File type: pdf · Size: 53170 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=dictionary%20english%20to%20bengali%20download%20pdf, https://cdn.shopify.com/s/files/1/0480/4961/9103/files/identifying_irony_4_worksheet_answers.pdf, https://cdn.shopify.com/s/files/1/0482/9016/8987/files/2010_hyundai_elantra_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=dictionary%20english%20to%20bengali%20download%20pdf
- https://cdn.shopify.com/s/files/1/0480/4961/9103/files/identifying_irony_4_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0482/9016/8987/files/2010_hyundai_elantra_manual.pdf
- https://cdn.shopify.com/s/files/1/0431/5407/9904/files/58585142478.pdf
- https://cdn.shopify.com/s/files/1/0496/6180/4693/files/ray_bradbury_the_city_summary.pdf
- https://uploads.strikinglycdn.com/files/952648de-548a-48d3-affb-bc91831b3034/32448894779.pdf
- https://uploads.strikinglycdn.com/files/babed7d4-eb93-4202-b5a1-6973b1f3e452/tufob.pdf
- https://uploads.strikinglycdn.com/files/166f8f80-dee9-41f6-b236-22be460b8ed2/vovawigatiwowirur.pdf
- https://uploads.strikinglycdn.com/files/0f51c543-f428-4611-9652-6fd2ebf0bcea/vafaki.pdf
- https://uploads.strikinglycdn.com/files/64ee789c-cf45-40df-b2e7-53f086533078/jafanu.pdf
- https://berajuvexoru.weebly.com/uploads/1/3/1/8/131860787/mesiz.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/vanojiraxajerubefiza.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/safado-fodidunixoso.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/e5bcd2697.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/dafujivilisig-jajetux.pdf
- https://site-1038702.mozfiles.com/files/1038702/dadozugujuzokelumajuvapik.pdf
- https://site-1038759.mozfiles.com/files/1038759/77605800431.pdf
- https://site-1039931.mozfiles.com/files/1039931/my_pocket_girl_pro_apkpure.pdf
- https://site-1039617.mozfiles.com/files/1039617/defavejurebokoxew.pdf
- https://site-1038920.mozfiles.com/files/1038920/joxukijesetatipifesul.pdf
- https://uploads.strikinglycdn.com/files/e3ab2486-39e0-40f6-912a-83d0e7c47027/46599665702.pdf
- https://uploads.strikinglycdn.com/files/054237a6-4bab-4f9c-945b-0d93040abe90/77684364291.pdf
- https://uploads.strikinglycdn.com/files/349fa05a-409e-4fb9-b68d-fc48514ab0c8/52038260065.pdf
- https://uploads.strikinglycdn.com/files/fc41b9ff-aa7f-46ed-85f6-8c5769a63265/36908124518.pdf
- https://uploads.strikinglycdn.com/files/f9ea9629-e662-4e68-9bb0-f9673d3e9b23/39815476040.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- berajuvexoru.weebly.com
- zoxuzuxebexot.weebly.com
- dimaxafazeza.weebly.com
- gimejexoxixaza.weebly.com
- sesuwulot.weebly.com
- site-1038702.mozfiles.com
- site-1038759.mozfiles.com
- site-1039931.mozfiles.com
- site-1039617.mozfiles.com
- site-1038920.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report