SUSPICIOUS — 5111542.pdf
SUSPICIOUS — 5111542.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e9bb50edaf60d35fa20cfaf1995f1709ef45070e3cdaf6569672ff4569bada1f - SHA-1:
a0c87ce7d6f8b7bcf082bac755af75524ca812ba - MD5:
311adf71579bbf4a3d3047e6d438a322 - ssdeep:
768:AgGzpDZp+1+vTFxUrY64RRMK6BipYkkgNSXbrWGlEoaklu9:NGFdp5fMK6BchwXbrWGlEjklu9 - TLSH:
T1C8326CF300A7ED8C7A8FAF43AAB71199614AD38D712396905888762CC5BC6FD7F00951 - Submitted as: 5111542.pdf
- File type: pdf · Size: 43304 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=minecraft%20ara%C3%A7%20modu, https://uploads.strikinglycdn.com/files/f5370922-3022-4b30-bf0b-fc46f8507269/11740097059.pdf, https://uploads.strikinglycdn.com/files/37865ace-3362-4d88-81d1-a6e39558cb87/71661730749.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=minecraft%20ara%C3%A7%20modu
- https://uploads.strikinglycdn.com/files/f5370922-3022-4b30-bf0b-fc46f8507269/11740097059.pdf
- https://uploads.strikinglycdn.com/files/37865ace-3362-4d88-81d1-a6e39558cb87/71661730749.pdf
- https://uploads.strikinglycdn.com/files/3dd15769-1fc3-4631-8f7f-620c5b3e6dec/vatudegagomizotakatedol.pdf
- https://uploads.strikinglycdn.com/files/9894c4d2-3168-4dbc-b2cd-3cec687203c4/paul_stainthorpe_facebook.pdf
- https://s3.amazonaws.com/zuxadol/januxatezemuberofukox.pdf
- https://cdn.shopify.com/s/files/1/0437/6412/1757/files/levapi.pdf
- https://cdn.shopify.com/s/files/1/0483/4233/5637/files/73926655950.pdf
- https://cdn.shopify.com/s/files/1/0266/9087/9667/files/lausd_parent_portal_instructions.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/73692456325.pdf
- https://uploads.strikinglycdn.com/files/72affdbe-ab90-4412-a8c6-04475009cb5a/horizons_bible_study.pdf
- https://uploads.strikinglycdn.com/files/fb10af7b-79b4-4fec-95f6-4ae13979bcc2/40336425692.pdf
- https://uploads.strikinglycdn.com/files/88d4c917-77e0-48f2-a14a-a088820164f7/godiwamesur.pdf
- https://uploads.strikinglycdn.com/files/374cd454-61ac-4918-a0cd-cad61af1a805/77412008961.pdf
- https://kafasomawupi.weebly.com/uploads/1/3/0/7/130775431/sewixemomer_kimexazij.pdf
- https://vodiwisilob.weebly.com/uploads/1/3/2/6/132681054/gomitamewegamigaji.pdf
- https://jonipafatanepa.weebly.com/uploads/1/3/2/7/132741476/vidubudinajubibuzuw.pdf
- https://nizesuvijeva.weebly.com/uploads/1/3/1/6/131607023/d84b99619a458.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/wewebunovemerifabo.pdf
- https://cdn.shopify.com/s/files/1/0268/8427/6415/files/18968984448.pdf
- https://cdn.shopify.com/s/files/1/0485/3320/9243/files/19280513270.pdf
- https://cdn.shopify.com/s/files/1/0434/3870/2748/files/ripag.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- kafasomawupi.weebly.com
- vodiwisilob.weebly.com
- jonipafatanepa.weebly.com
- nizesuvijeva.weebly.com
- jawasolasazilem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report