SUSPICIOUS — 04f6c.pdf
SUSPICIOUS — 04f6c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f13bf8aae38c2c5b78b40f96479d046866ea877f39187b44c93f02b894081bef - SHA-1:
b7b4077b9ff150ff8af060f0140393a4556c2e1e - MD5:
d73427f77dead79d0b92b0e26075a379 - ssdeep:
768:dgGzpDSpIm5nFls4oMkDaVZfTF6rpZM0Wr3iTYbMnzOnaaM0u1Ta1FLlYfRd:eGF+pIg4aV5EG2aaaM0uta7LlYfRd - TLSH:
T1BD326CF300A7DD0D7AC6DB43AEEE245E9189D7886132A660459C272CC4BC7BD7F40A61 - Submitted as: 04f6c.pdf
- File type: pdf · Size: 45259 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=remove%20shellac%20at%20home, https://site-1039563.mozfiles.com/files/1039563/dovibumujom.pdf, https://site-1042767.mozfiles.com/files/1042767/59801330361.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=remove%20shellac%20at%20home
- https://site-1039563.mozfiles.com/files/1039563/dovibumujom.pdf
- https://site-1042767.mozfiles.com/files/1042767/59801330361.pdf
- https://site-1043090.mozfiles.com/files/1043090/wugigewoda.pdf
- https://site-1041501.mozfiles.com/files/1041501/83735651632.pdf
- https://cdn.shopify.com/s/files/1/0496/0557/4819/files/manual_car_wash_vancouver.pdf
- https://cdn.shopify.com/s/files/1/0485/7790/4800/files/kidaw.pdf
- https://cdn.shopify.com/s/files/1/0266/8625/9388/files/33174113582.pdf
- https://cdn.shopify.com/s/files/1/0498/8675/7018/files/nadegomalowal.pdf
- https://cdn.shopify.com/s/files/1/0491/6051/9879/files/90343009896.pdf
- https://uploads.strikinglycdn.com/files/5ac73510-8870-42a0-a506-c53846ab193a/48395970205.pdf
- https://uploads.strikinglycdn.com/files/7e815eb4-9f31-4f3a-af70-c826e8fa208b/17980764483.pdf
- https://uploads.strikinglycdn.com/files/5bb05a21-355c-489a-aa18-66c87269fe7b/94195371248.pdf
- https://uploads.strikinglycdn.com/files/142cbec3-d2e7-4fe4-8c58-717ba0bb22e8/luxevifew.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/safunezijowefup-wuluvifolat.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/f638fda.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/3250b5961ed1.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/4867245.pdf
- https://cdn.shopify.com/s/files/1/0485/0270/2242/files/84411839717.pdf
- https://cdn.shopify.com/s/files/1/0435/4686/9911/files/pemozoroxe.pdf
- https://cdn.shopify.com/s/files/1/0500/7248/6076/files/9599296738.pdf
- https://cdn.shopify.com/s/files/1/0482/9265/9362/files/21325566662.pdf
- https://cdn.shopify.com/s/files/1/0437/8204/5853/files/flipped_math_calculus_5.2.pdf
- https://cdn.shopify.com/s/files/1/0484/0842/8704/files/10711046074.pdf
- https://cdn.shopify.com/s/files/1/0429/5757/0207/files/bb_concert_scale_alto_sax.pdf
Embedded domains
- cctraff.ru
- site-1039563.mozfiles.com
- site-1042767.mozfiles.com
- site-1043090.mozfiles.com
- site-1041501.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- xojerajap.weebly.com
- tajurasexir.weebly.com
- mojivimimujovo.weebly.com
- gimejexoxixaza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report