SUSPICIOUS — 0047b7cfd0.pdf
SUSPICIOUS — 0047b7cfd0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
df5d38f8212c5beba04dfc508583b96b21847121174817a9d57225e98088da1b - SHA-1:
bf75c54780033ff88051a92132d2387c28212b57 - MD5:
5976797686c83a1e737528cca6bef5fa - ssdeep:
768:fgGzpDYpGuL07y+BUSvapgagNCm6KNxUofUxWjnQ85+Wydc:oGF8pG2ZcNPUxSjkWydc - TLSH:
T108327DF760A3EC8CBA8B6B07AEBB05595049D78D6062D760088C772CD47CAFD6E50A11 - Submitted as: 0047b7cfd0.pdf
- File type: pdf · Size: 44193 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=causative%20exercises%20multiple%20choice, https://uploads.strikinglycdn.com/files/e7e1f700-c9f1-4590-8fdc-a4a469e072eb/rekin.pdf, https://uploads.strikinglycdn.com/files/7ceb7ed6-17fe-49d5-8d46-f8c1fdcb7b54/58072260894.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=causative%20exercises%20multiple%20choice
- https://uploads.strikinglycdn.com/files/e7e1f700-c9f1-4590-8fdc-a4a469e072eb/rekin.pdf
- https://uploads.strikinglycdn.com/files/7ceb7ed6-17fe-49d5-8d46-f8c1fdcb7b54/58072260894.pdf
- https://uploads.strikinglycdn.com/files/b2c19b6c-7039-4a1e-ab80-3de446a6e365/vinekureverurapo.pdf
- https://uploads.strikinglycdn.com/files/18969447-833d-42a6-ac74-e8fa42ad0081/zimavoguzuwe.pdf
- https://uploads.strikinglycdn.com/files/b2923a41-d39c-463b-abed-25e42dc77b8f/poxifiteku.pdf
- https://site-1039967.mozfiles.com/files/1039967/buzobavekidotopirotiturij.pdf
- https://site-1038313.mozfiles.com/files/1038313/leruvuzupa.pdf
- https://site-1039918.mozfiles.com/files/1039918/duwirerepuzaxasuwexazoniw.pdf
- https://site-1040363.mozfiles.com/files/1040363/lidigosepepo.pdf
- https://site-1044103.mozfiles.com/files/1044103/12680269502.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f86fef68f1cf.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f8765163b6dc.pdf
- https://cdn-cms.f-static.net/uploads/4367278/normal_5f876220c0c90.pdf
- https://cdn-cms.f-static.net/uploads/4366654/normal_5f87629b38259.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f87646ea00a9.pdf
- https://uploads.strikinglycdn.com/files/6bd2043a-8f29-49b8-9d6f-6e21aff7bc83/17634289596.pdf
- https://uploads.strikinglycdn.com/files/0a814b8b-9762-43ec-99fb-6b9ff854cd27/70687757035.pdf
- https://uploads.strikinglycdn.com/files/83a9122d-2ce4-42dd-93c5-703f30db377a/37192365208.pdf
- https://uploads.strikinglycdn.com/files/3f05f25f-9d8b-4f03-8508-1dc00b674d2c/8920643240.pdf
- https://cdn-cms.f-static.net/uploads/4369797/normal_5f8810df97a7e.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f87bb9b0a9c7.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f8820b04dca8.pdf
- https://uploads.strikinglycdn.com/files/5a30de6c-6491-4ada-9363-b45559f4e79b/rivexojugukuwevubukom.pdf
- https://uploads.strikinglycdn.com/files/a51c2b2c-c370-43ed-a725-fa2b9b39b24f/safapupis.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1039967.mozfiles.com
- site-1038313.mozfiles.com
- site-1039918.mozfiles.com
- site-1040363.mozfiles.com
- site-1044103.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report