SUSPICIOUS — a7dbd6c99.pdf
SUSPICIOUS — a7dbd6c99.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e24028afb92ef79fae468332790ad6f5720b7da40f4a0f94c7890b4c6b102dd5 - SHA-1:
22e637f16967c7469238c3b6e759dfb343ef678b - MD5:
56eaf497a287f263a67a8d357c32e9e2 - ssdeep:
768:DgGzpD0jWIJUML534i2WmNWo80hsxsnBMAStBU3fRrpWjzfeypC9RlZjlSZSXIr4:8GFoioB5qhO/o3fRtWveypCF5QZSXw4 - TLSH:
T1FE34BFF351A7EE4C3D87AB43AA7A1094654AD388703297A409C93B7CC8BC2BD7F51850 - Submitted as: a7dbd6c99.pdf
- File type: pdf · Size: 56421 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=manual%20for%20schumacher%20instant%20power, https://cdn-cms.f-static.net/uploads/4417519/normal_5f9c52b3e8bfc.pdf, https://cdn-cms.f-static.net/uploads/4383322/normal_5f8cc9c79d781.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=manual%20for%20schumacher%20instant%20power
- https://s3.amazonaws.com/fejififimaketo/iptv_smarters_apk_download.pdf
- https://s3.amazonaws.com/widuxade/emmure_the_complete_guide_to_needlework_rar.pdf
- https://cdn-cms.f-static.net/uploads/4417519/normal_5f9c52b3e8bfc.pdf
- https://s3.amazonaws.com/suxiweke/bill_nye_cells_worksheet_answer_key.pdf
- https://cdn-cms.f-static.net/uploads/4383322/normal_5f8cc9c79d781.pdf
- https://cdn-cms.f-static.net/uploads/4387931/normal_5f8d9cd833d41.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f8f516b81884.pdf
- https://uploads.strikinglycdn.com/files/17ecc78c-fa6b-4e6d-9374-8cbd1efee05c/lewis_structure_c3h8.pdf
- https://s3.amazonaws.com/pirosisob/91446844649.pdf
- https://cdn-cms.f-static.net/uploads/4375504/normal_5f9a23ab200fd.pdf
- https://uploads.strikinglycdn.com/files/802568bc-c400-4fdf-b592-e6c926998ee8/20610741154.pdf
- https://cdn-cms.f-static.net/uploads/4383704/normal_5f91f3212cfc7.pdf
- https://s3.amazonaws.com/kavitokolezub/gobitiridebejukojuzapijus.pdf
- https://cdn-cms.f-static.net/uploads/4383132/normal_5f9be237ccddd.pdf
- https://cdn-cms.f-static.net/uploads/4388432/normal_5f95000686998.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report