SUSPICIOUS — 91242.pdf
SUSPICIOUS — 91242.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1b60a955ad40f39eccf4b8342cf993f771066b49c7accffdaae6fe1283759af1 - SHA-1:
890efd580b0d11ef92f2b8a2285980e375ec4b83 - MD5:
82ae2fa8a47994c1f01daf9bf80a1cd3 - ssdeep:
768:6gGzpDpprapBBA95Op5PMw/ihl9xVFO3qUrlHhaz+lEtHA3FpGcS7grvfOivmIY6:nGF1prSBBAPcB+q8H8FZWWOi+IYBat - TLSH:
T105339EF31093ED8C7A4BAB03BDAB256D604AD78D5172E760448C772DC5BC6AD7E00A60 - Submitted as: 91242.pdf
- File type: pdf · Size: 50710 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20saucers%20speak%20pdf, https://cdn-cms.f-static.net/uploads/4369646/normal_5f887f1a226cd.pdf, https://cdn-cms.f-static.net/uploads/4368494/normal_5f88c7e7975c4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20saucers%20speak%20pdf
- https://cdn-cms.f-static.net/uploads/4369646/normal_5f887f1a226cd.pdf
- https://cdn-cms.f-static.net/uploads/4368494/normal_5f88c7e7975c4.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f881d0d27c5f.pdf
- https://cdn-cms.f-static.net/uploads/4371495/normal_5f89cc29b6d78.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f87153d43d59.pdf
- https://cdn.shopify.com/s/files/1/0266/9484/4588/files/digital_world_apk_obb.pdf
- https://cdn.shopify.com/s/files/1/0498/0195/3442/files/50260538740.pdf
- https://cdn.shopify.com/s/files/1/0500/6698/1059/files/75207557034.pdf
- https://cdn.shopify.com/s/files/1/0499/4868/8552/files/godfather_theme_piano_violin.pdf
- https://cdn.shopify.com/s/files/1/0435/7039/7352/files/wisconsin_daycare_licensing_forms.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/vuzerexokigigoretoti.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/e27909d0be.pdf
- https://nitiruminaxodax.weebly.com/uploads/1/3/0/7/130738633/57718d2c.pdf
- https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/6472802bf5f4c.pdf
- https://cdn.shopify.com/s/files/1/0482/9616/5534/files/welimogatejurafamejavo.pdf
- https://cdn.shopify.com/s/files/1/0429/8647/1587/files/get_to_know_your_lab_equipment_activity_answers.pdf
- https://cdn.shopify.com/s/files/1/0436/7125/7241/files/4582773869.pdf
- https://cdn-cms.f-static.net/uploads/4369163/normal_5f87fd79958e0.pdf
- https://cdn-cms.f-static.net/uploads/4370555/normal_5f889874bf7af.pdf
- https://cdn-cms.f-static.net/uploads/4371790/normal_5f88545d18f0a.pdf
- https://uploads.strikinglycdn.com/files/2411f98e-4012-4700-9800-ce66e8ca5ff4/strasser_killing_floor_2.pdf
- https://uploads.strikinglycdn.com/files/3fac33e7-d155-4141-ade3-703917dfcee1/36569371663.pdf
- https://uploads.strikinglycdn.com/files/7093ca3b-b280-4386-aa1c-d3a4ced2bfb8/jobopexafadusibeze.pdf
- https://uploads.strikinglycdn.com/files/f2ff4e34-ae53-4927-be18-02b3278277dd/weragudubuwigugasuwi.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- papunagaku.weebly.com
- gevafitasib.weebly.com
- nitiruminaxodax.weebly.com
- dojulukasinu.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report