SUSPICIOUS — 28cac2f6f2937.pdf
SUSPICIOUS — 28cac2f6f2937.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
eb59047175e776106d72b010cf4be655b8d523aec13fed17c8190ab7a145b232 - SHA-1:
22e8fa86ff5ad56db988671e375541b51917bd36 - MD5:
46a21af690923ba0877212188babf42b - ssdeep:
768:LgGzpDft4jH4xQHrLXNf5D7jYjF2BoWfyS50EAgEngOftN9PWZT2bDY:0GFbt4z2M/XPM54oWeLnrVN852fY - TLSH:
T16D34BFF361A3ED4825C69B475BB61838619ACA8C7522927088DC767CC4B82FDAF40931 - Submitted as: 28cac2f6f2937.pdf
- File type: pdf · Size: 57311 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=rte%20act%202009%20pdf%20in%20marathi, https://uploads.strikinglycdn.com/files/057a7014-a613-4b84-b05d-3431098bc19d/first_steps_in_music_theory.pdf, https://uploads.strikinglycdn.com/files/bd5c7cc9-6a7e-4358-bb41-8795967270e5/3229567674.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=rte%20act%202009%20pdf%20in%20marathi
- https://uploads.strikinglycdn.com/files/057a7014-a613-4b84-b05d-3431098bc19d/first_steps_in_music_theory.pdf
- https://uploads.strikinglycdn.com/files/bd5c7cc9-6a7e-4358-bb41-8795967270e5/3229567674.pdf
- https://uploads.strikinglycdn.com/files/406ee2f2-664e-4172-bbbf-3abb42370df6/34998285106.pdf
- https://cdn.shopify.com/s/files/1/0432/1050/6404/files/kupewenolani.pdf
- https://cdn.shopify.com/s/files/1/0496/8644/6239/files/leatherman_charge_tti_damascus.pdf
- https://ruxodinari.weebly.com/uploads/1/3/4/3/134377607/415626a03e029.pdf
- https://s3.amazonaws.com/zuxadol/kepimamedatojefetafiganer.pdf
- https://uploads.strikinglycdn.com/files/1f59597a-2cf1-4559-8d6b-fccae3e7f7ee/a_menace_sleeps_in_balouve.pdf
- https://uploads.strikinglycdn.com/files/b6308ac8-a29a-4d23-86ec-97e70436f564/sobotefo.pdf
- https://porelananov.weebly.com/uploads/1/3/0/7/130775759/c2926e035a3.pdf
- https://rogidalot.weebly.com/uploads/1/3/1/6/131636841/polibisupokave.pdf
- https://tafopolen.weebly.com/uploads/1/3/4/3/134396822/mijutiwotoberatoneb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- ruxodinari.weebly.com
- s3.amazonaws.com
- porelananov.weebly.com
- rogidalot.weebly.com
- tafopolen.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report