SUSPICIOUS — 7db3d9e7f.pdf
SUSPICIOUS — 7db3d9e7f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e6f8dd5f44ad8f2f07402f08380bf648395fd8c78a775ab04ebec426bc03ea59 - SHA-1:
6edad47b90d5574bdd23cc7728200f4aaceb3c5d - MD5:
5108559b2001d5a6b4c289536c827b57 - ssdeep:
768:TgGzpDep91ce2bgD21QOOdxwj3t7Cam35W73L+fN3K7bguTrZMYi/zbl:sGFSpBS3t7Cac5Mb6MbgWirbl - TLSH:
T13732AEF750E7DD8C7ACA8F63AEA70566A04AC289622697A050CD773CC4FC5BC5E50870 - Submitted as: 7db3d9e7f.pdf
- File type: pdf · Size: 43761 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=kitchen%20tools%20and%20equipment%20and%20their%20uses%20pdf, https://cdn-cms.f-static.net/uploads/4384304/normal_5f8e244d60353.pdf, https://cdn-cms.f-static.net/uploads/4368742/normal_5f91f6449b7a0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=kitchen%20tools%20and%20equipment%20and%20their%20uses%20pdf
- https://cdn-cms.f-static.net/uploads/4384304/normal_5f8e244d60353.pdf
- https://cdn-cms.f-static.net/uploads/4368742/normal_5f91f6449b7a0.pdf
- https://cdn-cms.f-static.net/uploads/4380209/normal_5f915d85dc5cb.pdf
- https://wesojejupeledaw.weebly.com/uploads/1/3/4/4/134446418/8224764.pdf
- https://cdn-cms.f-static.net/uploads/4402940/normal_5f9111ecc77d3.pdf
- https://cdn-cms.f-static.net/uploads/4384154/normal_5f908afee03d0.pdf
- https://cdn-cms.f-static.net/uploads/4368760/normal_5f886aec3f171.pdf
- https://cdn-cms.f-static.net/uploads/4379960/normal_5f90e6c4dfe4a.pdf
- https://cdn-cms.f-static.net/uploads/4368468/normal_5f8b3ada06d2b.pdf
- https://cdn-cms.f-static.net/uploads/4402932/normal_5f9212d800f74.pdf
- https://cdn-cms.f-static.net/uploads/4380531/normal_5f8de45328ee3.pdf
- https://cdn.shopify.com/s/files/1/0428/9118/2243/files/multimodal_transport_system.pdf
- https://cdn.shopify.com/s/files/1/0481/9474/8573/files/zug_um_zug_regeln.pdf
- https://uploads.strikinglycdn.com/files/d88f1e23-55e5-487f-8c05-507730f752cc/zerisugafenamiso.pdf
- https://uploads.strikinglycdn.com/files/5c3f645c-24c0-40f6-87f1-29339a64dbc9/gowojopugetulikusowowizu.pdf
- https://uploads.strikinglycdn.com/files/495c6043-60ed-43f9-96ff-57a1f6f408f0/fajox.pdf
- https://uploads.strikinglycdn.com/files/571a1161-fce4-417e-a9e5-5b6b6fa938c3/72662314729.pdf
- https://uploads.strikinglycdn.com/files/78c0eb67-823f-4c97-bad0-98aa3ab6c64f/wondershare_quiz_creator_registratio.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- wesojejupeledaw.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report