SUSPICIOUS — masijawaf.pdf
SUSPICIOUS — masijawaf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ea3db2efd183fd8d27fd66a41ba6dd98fdf08b2fcb0bc1ec221887a9845e9ffe - SHA-1:
5290e43f7425be2fef150695a4269490387ac228 - MD5:
351152b34ef2fcbd3c4ce7aee9fbf4c5 - ssdeep:
768:3gGzpDCpCgL9A6uAUU5Ceq11Hb2AnNSBhAjqSiuaFHqKOQQO9T8tZzIKd6XgKS3T:QGF+p99QAUUQx/9Ot8tCq6rS3Y4 - TLSH:
T107328CF34063EC4D7B87EB136DEA24599549EB88A132D661098C773CC97C67D3E10A60 - Submitted as: masijawaf.pdf
- File type: pdf · Size: 43708 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=carnatic%20music%20tutorial%20pdf, https://cdn-cms.f-static.net/uploads/4369909/normal_5f8a1195def38.pdf, https://cdn-cms.f-static.net/uploads/4369905/normal_5f8bebcebd6d0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=carnatic%20music%20tutorial%20pdf
- https://cdn-cms.f-static.net/uploads/4369909/normal_5f8a1195def38.pdf
- https://cdn-cms.f-static.net/uploads/4369905/normal_5f8bebcebd6d0.pdf
- https://cdn-cms.f-static.net/uploads/4369631/normal_5f8b8fd6e0a1c.pdf
- https://cdn.shopify.com/s/files/1/0481/9599/3754/files/89113387653.pdf
- https://cdn.shopify.com/s/files/1/0501/8304/5293/files/texuremexibabat.pdf
- https://cdn.shopify.com/s/files/1/0429/1523/3948/files/kagorokuvuti.pdf
- https://cdn.shopify.com/s/files/1/0431/1770/7413/files/homework_and_practice_workbook_answers_6th_grade.pdf
- https://cdn.shopify.com/s/files/1/0469/4963/0113/files/intex_pool_hoses_near_me.pdf
- https://cdn.shopify.com/s/files/1/0430/7084/9181/files/the_basic_elements_of_a_form_are_called.pdf
- https://cdn-cms.f-static.net/uploads/4366646/normal_5f87da88a7485.pdf
- https://cdn-cms.f-static.net/uploads/4367625/normal_5f882ba3d975b.pdf
- https://cdn.shopify.com/s/files/1/0428/5949/5590/files/wanted_enemy_metal_captain.pdf
- https://cdn.shopify.com/s/files/1/0266/7790/3560/files/dog_poop_color_guide.pdf
- https://cdn.shopify.com/s/files/1/0498/7981/0203/files/gitapezivorexorelepaj.pdf
- https://cdn.shopify.com/s/files/1/0486/0752/7077/files/lerifawudatujabar.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/how_to_upload_image_using_retrofit_android.pdf
- https://cdn.shopify.com/s/files/1/0502/8410/1804/files/candy_crush_2020_download_apk.pdf
- https://cdn.shopify.com/s/files/1/0436/9891/3435/files/vp_hr_job_titles.pdf
- https://cdn.shopify.com/s/files/1/0433/6680/9765/files/canon_pixma_mg3620_price.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report