SUSPICIOUS — 218c5b8.pdf
SUSPICIOUS — 218c5b8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
15348d57d7a6a3b0a73a214e33860f4b6f1db292010ef3145c896c7ce7eb4930 - SHA-1:
4bed71f4bdcde47f91d81fa5fb3fd901a6fc983e - MD5:
6a726c8f763868f6372de7dd6da1974f - ssdeep:
768:CgGzpDAelTuJF9yU9i7nMubGQG23cZzIDrU28Wl/gljRiKy6wIq0F:fGFceKiLxyh+Ez2rmWloltjy6dq0F - TLSH:
T1DA327DF75097ED8C768BAB036DF61099618AD7883123DBA448C8772CC47C6BDBE10951 - Submitted as: 218c5b8.pdf
- File type: pdf · Size: 46711 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=subject%20verb%20agreement%20with%20collective%20nouns%20worksheet%20pdf, https://cdn-cms.f-static.net/uploads/4387929/normal_5f8d3575621e3.pdf, https://cdn-cms.f-static.net/uploads/4372073/normal_5f8ce0878d88a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=subject%20verb%20agreement%20with%20collective%20nouns%20worksheet%20pdf
- https://cdn-cms.f-static.net/uploads/4387929/normal_5f8d3575621e3.pdf
- https://cdn-cms.f-static.net/uploads/4372073/normal_5f8ce0878d88a.pdf
- https://cdn-cms.f-static.net/uploads/4368777/normal_5f8800a06065f.pdf
- https://uploads.strikinglycdn.com/files/df20461d-ba22-4c09-8d7e-311872c13289/16530744085.pdf
- https://uploads.strikinglycdn.com/files/bd528026-843f-4ce8-b8e6-7b62436d02bf/83671009565.pdf
- https://uploads.strikinglycdn.com/files/945daa59-cc02-4991-9206-f0278d4c2541/petaxitixumabenosoto.pdf
- https://uploads.strikinglycdn.com/files/5d54278a-74ed-428f-b96f-b8446a6f60c5/bdo_tier_4_pets.pdf
- https://uploads.strikinglycdn.com/files/7d816076-0bec-4dcc-876b-7061f8415bc7/89513771315.pdf
- https://uploads.strikinglycdn.com/files/4109db73-fd2b-4f2c-8bb9-60238be43f07/tu_hi_mera_pyar_gori_mp3_song_downlo.pdf
- https://uploads.strikinglycdn.com/files/da3952b4-9779-4c31-9510-cab569e8d41e/36381874733.pdf
- https://uploads.strikinglycdn.com/files/0f078119-8b33-4b01-a2b7-830d5cfa97a9/44300158500.pdf
- https://uploads.strikinglycdn.com/files/09adc9ce-12e9-439a-8af2-32ab48770eb7/personal_firearms_record_sheet.pdf
- https://uploads.strikinglycdn.com/files/1ba81904-f199-4b4b-b330-56085676b26e/79423267831.pdf
- https://uploads.strikinglycdn.com/files/c37cb15e-d89f-4379-9bde-16c4f2d276d4/67971414692.pdf
- https://uploads.strikinglycdn.com/files/8703546a-71f0-4336-b884-c339127c666e/kenase.pdf
- https://uploads.strikinglycdn.com/files/ac739fef-82af-4531-a178-eca2e46cc1e2/71758941344.pdf
- https://uploads.strikinglycdn.com/files/7c09d11e-3135-462c-a981-8b203a1908c9/aprende_a_dibujar_comic_hermosas_mujeres.pdf
- https://cdn.shopify.com/s/files/1/0268/7598/6116/files/persian_alphabet_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0467/8038/3385/files/1306978311.pdf
- https://cdn.shopify.com/s/files/1/0500/4791/0052/files/39245512016.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report