SUSPICIOUS — 758a90.pdf
SUSPICIOUS — 758a90.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
eafc6ed06493d6726581d0bc911fc2e1d146418aba205810b9f8332037f78db3 - SHA-1:
59e1db936182ec00c0c7136ed62d1e7135ade120 - MD5:
09c95b9709f258b8b948afb24112dfe4 - ssdeep:
768:BgGzpDupcxVondh8d+b65AKKmGdDeowBDNbrPhVYs6Rr+ojK8Di9XEIYA+kn/:yGF6pFJBdDeTBDprp5Wr+WK8MEq/ - TLSH:
T102329FF71493ED4C3A869B039DAB2579258AD388212797A0458C237CD4FC67EBF20970 - Submitted as: 758a90.pdf
- File type: pdf · Size: 44817 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=lincoln%20navigator%20performance%20upgrades, https://cdn-cms.f-static.net/uploads/4366367/normal_5f87708c16450.pdf, https://cdn-cms.f-static.net/uploads/4366661/normal_5f87465f8e402.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=lincoln%20navigator%20performance%20upgrades
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f87708c16450.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f87465f8e402.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8786731f598.pdf
- https://cdn.shopify.com/s/files/1/0266/8373/6238/files/learning_to_read_malcolm_x_citation.pdf
- https://cdn.shopify.com/s/files/1/0483/0504/5659/files/wetoxa.pdf
- https://cdn.shopify.com/s/files/1/0432/2626/7816/files/the_world_on_turtles_back.pdf
- https://cdn.shopify.com/s/files/1/0481/6316/0231/files/sirewedomilupiturareke.pdf
- https://uploads.strikinglycdn.com/files/466637e1-917b-4cd9-9e93-3709345dde5b/2129852463.pdf
- https://uploads.strikinglycdn.com/files/79f83fb0-3727-4a75-aae2-a19a285131ca/97876094769.pdf
- https://uploads.strikinglycdn.com/files/65060a01-2d23-4bf1-90f0-b4b6ab34758b/82646074247.pdf
- https://uploads.strikinglycdn.com/files/d3099ca0-e921-4012-afa4-2b86df2e1a42/40087771559.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f874de8d76b2.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f8825a8eb358.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f871db1adeab.pdf
- https://cdn-cms.f-static.net/uploads/4369328/normal_5f87bc5185548.pdf
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f87649078c51.pdf
- https://uploads.strikinglycdn.com/files/7f82e6d7-5530-407a-b37e-c58f137aa6c6/wukekefajer.pdf
- https://uploads.strikinglycdn.com/files/2ea69cea-7e85-4a37-80f5-335333d25b45/gutojarute.pdf
- https://uploads.strikinglycdn.com/files/eefa7ca2-6957-45de-8f20-f380563167a1/ruvububonigobofox.pdf
- https://site-1037886.mozfiles.com/files/1037886/rujuvaranumixifobi.pdf
- https://site-1044236.mozfiles.com/files/1044236/kalexofunatum.pdf
- https://site-1040663.mozfiles.com/files/1040663/balubisizamumaxejerukiwe.pdf
- https://site-1039784.mozfiles.com/files/1039784/80877332124.pdf
- https://site-1040398.mozfiles.com/files/1040398/kaguxawulobax.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1037886.mozfiles.com
- site-1044236.mozfiles.com
- site-1040663.mozfiles.com
- site-1039784.mozfiles.com
- site-1040398.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report