SUSPICIOUS — d81b7.pdf
SUSPICIOUS — d81b7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
1397a49debc903b450cf327f5af1d3020afb27cc591f57075147334583541c5f - SHA-1:
ecb685638da620572635031e877ac2e5118aac81 - MD5:
ef993f945f66ae1b262c976b5f774723 - ssdeep:
768:SgGzpDypODiXu8GgJ8L/KxPgczvTaYH7GY+5b0AfTycWbjt:PGF+pRHxPgczvTaYHKYE0AfTJWbjt - TLSH:
T14D307DF75097ED8C7A8F6F139EFB15A9A04AC289613396A0508C772CC47C5EC2E10964 - Submitted as: d81b7.pdf
- File type: pdf · Size: 37681 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=kent%20repertory%20pdf, https://uploads.strikinglycdn.com/files/dd96cf8b-bcf0-44f7-a882-12d5f140b0e9/52931470046.pdf, https://uploads.strikinglycdn.com/files/a49a75cb-b26d-4288-82de-02a99793071d/115260560.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=kent%20repertory%20pdf
- https://uploads.strikinglycdn.com/files/dd96cf8b-bcf0-44f7-a882-12d5f140b0e9/52931470046.pdf
- https://uploads.strikinglycdn.com/files/a49a75cb-b26d-4288-82de-02a99793071d/115260560.pdf
- https://uploads.strikinglycdn.com/files/8e25dcea-83a5-480c-82f7-fdf27cf1925a/jijajifag.pdf
- https://uploads.strikinglycdn.com/files/87bbdac7-1807-444c-a55d-732eb81bc393/64278303708.pdf
- https://uploads.strikinglycdn.com/files/a2daac71-66df-4ee9-8d21-4088753b6fc0/3437192481.pdf
- https://uploads.strikinglycdn.com/files/e1155560-898f-494d-ab1f-732d611cfa0d/vitotejitopifel.pdf
- https://uploads.strikinglycdn.com/files/c2c82552-ddef-4061-80a3-6146828d23b3/zajijipa.pdf
- https://uploads.strikinglycdn.com/files/e4c9c2da-9743-443f-a270-b2362bdfefe0/novanifadasomawobotopapa.pdf
- https://uploads.strikinglycdn.com/files/39fdf5b1-0fc9-4c5d-97ee-abbe7995e3f1/30546750293.pdf
- https://uploads.strikinglycdn.com/files/38299b13-28de-4a00-a846-5282935612ea/54406707394.pdf
- https://uploads.strikinglycdn.com/files/5ca3d62b-1190-417a-9d38-b935f827212b/keludekizojirazu.pdf
- https://uploads.strikinglycdn.com/files/d44be58f-c95b-4bf9-a739-3d565c629a2a/dovufewudidopeka.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f873539b6eaf.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f87195f395f8.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f883e121155f.pdf
- https://cdn-cms.f-static.net/uploads/4367911/normal_5f87f5c492f36.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f880223bdd95.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f87a661eba0a.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f873f30e4aba.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report