SUSPICIOUS — 81c6d55c1488956.pdf
SUSPICIOUS — 81c6d55c1488956.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
fbd021e3324c46df3da0410b5077768dfce7c3edcd32d815ea0c091e71f8fc18 - SHA-1:
9b28e1a6847179c1a3ae9cf8626b5f57f712e0da - MD5:
9d00179b5acba90a786777e22058fb00 - ssdeep:
1536:aGFrpj3yrcKapIAmUqAkxkjlt8AQT9HgFKSWS:DFrp+wK3Lpxkjwl9HgFKQ - TLSH:
T17D338DF71083EC8D7E8B9B836EB71195658A8B887232976008DC766CD17C6BC7F105A1 - Submitted as: 81c6d55c1488956.pdf
- File type: pdf · Size: 50269 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=salgsanvisning%20af%20varer%20p%C3%A5%20college%202, https://cdn.shopify.com/s/files/1/0492/0079/1715/files/don_quijote_temas_principales_y_secundarios.pdf, https://cdn.shopify.com/s/files/1/0500/3028/0864/files/91554273817.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=salgsanvisning%20af%20varer%20p%C3%A5%20college%202
- https://cdn.shopify.com/s/files/1/0492/0079/1715/files/don_quijote_temas_principales_y_secundarios.pdf
- https://cdn.shopify.com/s/files/1/0500/3028/0864/files/91554273817.pdf
- https://cdn.shopify.com/s/files/1/0481/6316/0231/files/high_school_digital_art_syllabus.pdf
- https://uploads.strikinglycdn.com/files/daf9068c-4354-45fa-8769-ab121db255bd/tipefiwirotugufulaj.pdf
- https://uploads.strikinglycdn.com/files/4a08d4db-1789-463e-a7c7-16aa81993272/tadev.pdf
- https://site-1043607.mozfiles.com/files/1043607/76164789059.pdf
- https://site-1036869.mozfiles.com/files/1036869/kebexeja.pdf
- https://site-1042010.mozfiles.com/files/1042010/501680660.pdf
- https://site-1038913.mozfiles.com/files/1038913/mibifomodaweroliwadive.pdf
- https://cdn.shopify.com/s/files/1/0431/0371/5489/files/burogekudilelojifon.pdf
- https://cdn.shopify.com/s/files/1/0499/3299/2674/files/ike_smash_bros_moves.pdf
- https://cdn.shopify.com/s/files/1/0498/6109/9675/files/haunted_house_images_download.pdf
- https://cdn.shopify.com/s/files/1/0496/7894/2360/files/19533472669.pdf
- https://cdn.shopify.com/s/files/1/0494/1696/2215/files/pelham_library_hours.pdf
- https://uploads.strikinglycdn.com/files/9d4be064-c0d0-467c-8872-10c694548711/kipewozegot.pdf
- https://uploads.strikinglycdn.com/files/a8fd9a0f-e8f9-40bd-9ebd-918c307443ee/66148225762.pdf
- https://uploads.strikinglycdn.com/files/2379fcee-211d-43c1-97da-fd5e511188fe/memuxedidafisilizaxig.pdf
- https://uploads.strikinglycdn.com/files/4cd57a97-2af0-4243-b735-108a0aff0228/8357614771.pdf
- https://uploads.strikinglycdn.com/files/59742c20-ca23-40f7-a936-3c8b4688b04a/neroremotobivu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1043607.mozfiles.com
- site-1036869.mozfiles.com
- site-1042010.mozfiles.com
- site-1038913.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report