SUSPICIOUS — 393e0.pdf
SUSPICIOUS — 393e0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1b360a7592551629b98dc8d7564c8304228c19fc3b58eafa951812cfabe2c93b - SHA-1:
7fa937ef9f2291475081e90c4e59e0958623d0e5 - MD5:
a7e2c29b010eead474177d73f6868c4d - ssdeep:
1536:bGFappoGjnHP/3Dokrb7B/Mj6kkkDMEg:6FapyGrv7okrXBEj6kkt - TLSH:
T12E349EF310A7EE4C7B8B6F876DE61169604AC689612297A044CC3B6CD17C6FE7F00652 - Submitted as: 393e0.pdf
- File type: pdf · Size: 54894 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=my%20hero%20academia%20the%20movie%20english%20dub%20google%20docs, https://uploads.strikinglycdn.com/files/febe92a6-5358-4f1b-9a72-95b5411587e6/bozusosup.pdf, https://uploads.strikinglycdn.com/files/9a9eb4e5-773f-455c-96b9-12fd13e6465a/vesatekivivepoketifiku.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=my%20hero%20academia%20the%20movie%20english%20dub%20google%20docs
- https://uploads.strikinglycdn.com/files/febe92a6-5358-4f1b-9a72-95b5411587e6/bozusosup.pdf
- https://uploads.strikinglycdn.com/files/9a9eb4e5-773f-455c-96b9-12fd13e6465a/vesatekivivepoketifiku.pdf
- https://uploads.strikinglycdn.com/files/99419995-07ed-44d1-a33d-d223e15712c2/5430359729.pdf
- https://uploads.strikinglycdn.com/files/9c02de5a-d385-4e54-aeed-920b1bb09b6a/56888926001.pdf
- https://site-1039525.mozfiles.com/files/1039525/mevot.pdf
- https://site-1040513.mozfiles.com/files/1040513/46046818048.pdf
- https://site-1048168.mozfiles.com/files/1048168/jajumedajuw.pdf
- https://site-1044148.mozfiles.com/files/1044148/acls_manual_online_free.pdf
- https://site-1041766.mozfiles.com/files/1041766/79301798957.pdf
- https://cdn-cms.f-static.net/uploads/4369313/normal_5f87adf7a3889.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f8712a5491c5.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f87873f95b1b.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f87092ca0179.pdf
- https://cdn-cms.f-static.net/uploads/4367905/normal_5f876596bdb51.pdf
- https://cdn.shopify.com/s/files/1/0430/9444/2145/files/zikikesaxupet.pdf
- https://cdn.shopify.com/s/files/1/0493/4906/6911/files/how_to_hack_drag_racing_streets.pdf
- https://cdn.shopify.com/s/files/1/0434/8506/9477/files/woodbury_county_iowa.pdf
- https://cdn.shopify.com/s/files/1/0493/6820/3430/files/madrona_elementary_school_edmonds.pdf
- https://site-1039578.mozfiles.com/files/1039578/wosurikesu.pdf
- https://site-1044207.mozfiles.com/files/1044207/trigonometry_workbook_for_dummies.pdf
- https://site-1037113.mozfiles.com/files/1037113/47208634033.pdf
- https://cdn.shopify.com/s/files/1/0435/2435/8298/files/whynter_arc-12s_manual.pdf
- https://cdn.shopify.com/s/files/1/0496/0780/3029/files/input_output_devices_mcq.pdf
- https://cdn.shopify.com/s/files/1/0428/1139/2167/files/67081458955.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1039525.mozfiles.com
- site-1040513.mozfiles.com
- site-1048168.mozfiles.com
- site-1044148.mozfiles.com
- site-1041766.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1039578.mozfiles.com
- site-1044207.mozfiles.com
- site-1037113.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report