SUSPICIOUS — 30546373742.pdf
SUSPICIOUS — 30546373742.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
f041918d715af6c6e582de9ea67a93feef5bf931691e44ff71797f6a24afe060 - SHA-1:
d5b23e83bfb27daf8cdd52fddc8040e42ed12240 - MD5:
d1ab5e1eb78d9d1d2585cc5288fb3549 - ssdeep:
768:JgGzpDIpp9Wn7mL5YSGPuv9Zi+45pVnvERaz2oZCes9tdpyINzela+:qGF8pRv9k+45XvEIiXesLxela+ - TLSH:
T117328EF32097ED4C7A8BAF43ADAE3559904AD3496032E2648588372DC47CBBD6F50A10 - Submitted as: 30546373742.pdf
- File type: pdf · Size: 43335 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=cities+skylines+traffic+manager, https://uploads.strikinglycdn.com/files/eaa4e17d-9e88-4210-a650-a1acd8bdd4a7/jakopuzuruxikubewawapot.pdf, https://uploads.strikinglycdn.com/files/732c0856-ea02-45d8-98e4-0bdc8af58a67/pafituwe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=cities+skylines+traffic+manager
- https://uploads.strikinglycdn.com/files/eaa4e17d-9e88-4210-a650-a1acd8bdd4a7/jakopuzuruxikubewawapot.pdf
- https://uploads.strikinglycdn.com/files/732c0856-ea02-45d8-98e4-0bdc8af58a67/pafituwe.pdf
- https://uploads.strikinglycdn.com/files/9b56c126-c9cd-41d9-aa2f-1ab1b93c4cc6/basovazinek.pdf
- https://cdn.shopify.com/s/files/1/0484/7478/3906/files/panama_buena_vista_school_district_board_meeting.pdf
- https://cdn.shopify.com/s/files/1/0484/2992/4509/files/25398562676.pdf
- https://cdn.shopify.com/s/files/1/0435/6489/2323/files/whatsapp_online_offline_notification_apk_free.pdf
- https://cdn.shopify.com/s/files/1/0482/0992/0154/files/small_chef_salad_calories.pdf
- https://cdn.shopify.com/s/files/1/0480/2337/1935/files/the_land_of_open_graves_free.pdf
- https://cdn.shopify.com/s/files/1/0434/9601/3990/files/marie_kondo_doblar_camisas_manga_larga.pdf
- https://cdn.shopify.com/s/files/1/0485/0162/0898/files/getububo.pdf
- https://cdn.shopify.com/s/files/1/0496/5587/3699/files/lawuzixejunej.pdf
- https://uploads.strikinglycdn.com/files/605094ed-c574-4e74-9fdd-5cbed99b9f5b/tenevubelozudu.pdf
- https://uploads.strikinglycdn.com/files/9239d03b-f576-4334-b2ee-63c358a2e559/74621961005.pdf
- https://uploads.strikinglycdn.com/files/2a2a0d96-0947-4f6a-856d-d0b88b8da032/visenosuzomujemutinigoj.pdf
- https://uploads.strikinglycdn.com/files/5e8f3e32-cb37-4b4f-98cb-bacd4286f82a/pubudozufezobofad.pdf
- https://uploads.strikinglycdn.com/files/0abe0511-b8d7-408f-91fe-26cfda2ca1f8/lenalage.pdf
- https://uploads.strikinglycdn.com/files/3510609a-fa14-43b2-b6c9-da3649a1fa9b/92637609766.pdf
- https://uploads.strikinglycdn.com/files/97508920-7b73-4bf0-80c9-06cfb25347ef/59909709192.pdf
- https://uploads.strikinglycdn.com/files/42ff8a87-8830-491a-9c1d-fa524151df5e/35534706173.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report