SUSPICIOUS — 9676963.pdf
SUSPICIOUS — 9676963.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
0ecf61969fbe521d9adc1a1e690d7d4a607eb320f63c2fc5d00e6fdfe3cdb517 - SHA-1:
e531ecc15ad069e74cab44db8c294452f9258ecb - MD5:
ebb36fbb122d3a614320ffbfdf8496b1 - ssdeep:
1536:FGFepiH0ibketPjgyLjWbCzdBIvmRHdBnTcwAQBMSrM:YFepiUibh0yLjWMf9BTcMMn - TLSH:
T14936BFF350A7ED4C3B8B2F836AA7105A608EC3CD613697A0158C272DE47C6AC7E41A51 - Submitted as: 9676963.pdf
- File type: pdf · Size: 63435 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=irregular%20verbs%20spanish, https://uploads.strikinglycdn.com/files/5ef0122a-4f81-445c-8704-14a34cc14d28/58552307542.pdf, https://uploads.strikinglycdn.com/files/43ee1b4d-34de-4e8e-8448-9472b50abed1/77956094287.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=irregular%20verbs%20spanish
- https://uploads.strikinglycdn.com/files/5ef0122a-4f81-445c-8704-14a34cc14d28/58552307542.pdf
- https://uploads.strikinglycdn.com/files/43ee1b4d-34de-4e8e-8448-9472b50abed1/77956094287.pdf
- https://uploads.strikinglycdn.com/files/fb88d7e0-7826-47f7-8cb4-b7016cb689e6/73628879416.pdf
- https://uploads.strikinglycdn.com/files/d85b0801-85d9-4755-94aa-4b06db5bb843/nalozinib.pdf
- https://cdn.shopify.com/s/files/1/0266/7698/6034/files/vurugiwutoriponegagu.pdf
- https://cdn.shopify.com/s/files/1/0500/5505/3472/files/sakuvumumajunizevaremip.pdf
- https://cdn.shopify.com/s/files/1/0485/0601/1809/files/rifigi.pdf
- https://cdn.shopify.com/s/files/1/0427/8072/1311/files/ford_escape_owners_manual_2020.pdf
- https://cdn.shopify.com/s/files/1/0484/0488/9760/files/zalerisoxifirokexalumeno.pdf
- https://cdn.shopify.com/s/files/1/0483/7992/0537/files/generos_dela_literatura_infantil.pdf
- https://cdn.shopify.com/s/files/1/0485/0060/5089/files/saw_games_simpsons_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0478/1791/6575/files/urban_dictionary_words_for_sex_acts.pdf
- https://cdn.shopify.com/s/files/1/0435/0240/3750/files/lookout_mountain_elementary_school_supply_list.pdf
- https://cdn.shopify.com/s/files/1/0433/4908/2264/files/bowupufemamurunumonuwufu.pdf
- https://cdn.shopify.com/s/files/1/0432/9583/4280/files/bifen_i_t_insecticide.pdf
- https://cdn.shopify.com/s/files/1/0486/9718/0310/files/79688560664.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f874a5f3369f.pdf
- https://cdn-cms.f-static.net/uploads/4367952/normal_5f876ee2ebf58.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f86f52423c9c.pdf
- https://cdn-cms.f-static.net/uploads/4366319/normal_5f8788b9baf71.pdf
- https://cdn-cms.f-static.net/uploads/4366027/normal_5f87e1150184e.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f87a27d20017.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f87bfdf4ba42.pdf
- https://cdn-cms.f-static.net/uploads/4366623/normal_5f8738a85e206.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report