SUSPICIOUS — 7050282.pdf
SUSPICIOUS — 7050282.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f85e7afd533bd8750e73a72b73496104b27bad9c044efbdf23ba091f6b54c86d - SHA-1:
4c4ef2b1a8f04079db8c8c37763882e431b3fa37 - MD5:
c84d286e1ecb6975907da1ba98490182 - ssdeep:
768:0gGzpDfp77rnKb994WnIsvk+HD8U0Y5RV+T+QVE0vBG:BGFTp3+74WnIQfD8+5rW+uE0vBG - TLSH:
T105306DF35097EC8C7A8BAB035DBB159DA14ED389A136D39045887B2DD47CAFC6E00A50 - Submitted as: 7050282.pdf
- File type: pdf · Size: 39161 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=lindt%20truffle%20flavor%20guide, https://site-1048557.mozfiles.com/files/1048557/jawuniferigekovi.pdf, https://site-1036695.mozfiles.com/files/1036695/42199378204.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=lindt%20truffle%20flavor%20guide
- https://site-1048557.mozfiles.com/files/1048557/jawuniferigekovi.pdf
- https://site-1036695.mozfiles.com/files/1036695/42199378204.pdf
- https://site-1039179.mozfiles.com/files/1039179/detitipunezobiwun.pdf
- https://site-1039498.mozfiles.com/files/1039498/riwuzejovakokisatap.pdf
- https://site-1044103.mozfiles.com/files/1044103/93484086327.pdf
- https://uploads.strikinglycdn.com/files/e0091dbf-8cc8-4fd0-a840-53d35077c335/pefobago.pdf
- https://uploads.strikinglycdn.com/files/746e4ec5-25b5-409e-8512-1105f965306c/71347990519.pdf
- https://uploads.strikinglycdn.com/files/c56bc6b1-6e9f-452c-b08b-ed18b584ae42/xevopus.pdf
- https://uploads.strikinglycdn.com/files/e52b0ee5-19be-414f-808a-21d05fde4d9c/busizixim.pdf
- https://uploads.strikinglycdn.com/files/361cd715-0f94-4330-a64d-988b50e7c833/nipemilusadokasun.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/zevoginagetutag.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/zegomotagenig.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/pimemelaju-galewiwimav-zefugififirod.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/4230817.pdf
- https://uploads.strikinglycdn.com/files/493eb4c7-b5ed-4919-9119-52bb40771704/legikulisepozobuvof.pdf
- https://uploads.strikinglycdn.com/files/981f4e2e-5084-457b-9f1b-9eeb7cc11a75/66242996216.pdf
- https://uploads.strikinglycdn.com/files/7e684be1-8cdf-4064-bb77-67da879a2caf/13268763115.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/ff5aa.pdf
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/54c86654.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/kasawo-rakereroboxit-wuzunirib-midagawatebogef.pdf
- https://kuwofepex.weebly.com/uploads/1/3/2/7/132740654/e87b1fd2.pdf
- https://cdn-cms.f-static.net/uploads/4369329/normal_5f87cbec841c3.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f887da1d9302.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- site-1048557.mozfiles.com
- site-1036695.mozfiles.com
- site-1039179.mozfiles.com
- site-1039498.mozfiles.com
- site-1044103.mozfiles.com
- uploads.strikinglycdn.com
- pevugubak.weebly.com
- jawowigo.weebly.com
- rimesozarabef.weebly.com
- rezizeme.weebly.com
- nogafuku.weebly.com
- wonigebegi.weebly.com
- jamuseramomuf.weebly.com
- kuwofepex.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report