SUSPICIOUS — 9009541.pdf
SUSPICIOUS — 9009541.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2836b29195087b82c6110b44a04fbb23885ee887a525a2aa3125bb88031d5413 - SHA-1:
d44da06bab93073c3569514642ebd5f60fa90dea - MD5:
5994aad6b772fd929cce999c910d9aa4 - ssdeep:
768:OgGzpDMpAGPoULatO4uLbxj6tMxC9WCtNLNFx/telCyGsT1wvQbxenHbeFZ:rGFApR3x/xKjLFwl/pHwnHbeFZ - TLSH:
T19B317DF350A7EC8CBB4F6B039EAB1099618A83497076E66054D8376DD47C6FD2F00961 - Submitted as: 9009541.pdf
- File type: pdf · Size: 41792 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=from%20hell%20pdf, https://site-1040006.mozfiles.com/files/1040006/zorutaloxuzofok.pdf, https://site-1044010.mozfiles.com/files/1044010/54514221491.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=from%20hell%20pdf
- https://site-1040006.mozfiles.com/files/1040006/zorutaloxuzofok.pdf
- https://site-1044010.mozfiles.com/files/1044010/54514221491.pdf
- https://site-1041286.mozfiles.com/files/1041286/94003981428.pdf
- https://site-1039727.mozfiles.com/files/1039727/the_millennium_wolves.pdf
- https://cdn.shopify.com/s/files/1/0486/3809/9614/files/magnavox_32_inch_flat_screen_tv_manual.pdf
- https://cdn.shopify.com/s/files/1/0482/7578/3842/files/90136542547.pdf
- https://cdn.shopify.com/s/files/1/0432/6123/1262/files/steel_wool_mice.pdf
- https://uploads.strikinglycdn.com/files/32fe5084-67aa-493e-9bf7-dd2bdc1771ee/bijurujipawotumedidaf.pdf
- https://uploads.strikinglycdn.com/files/a851e3f8-e338-4518-b1fb-1cb758c0191b/16615545361.pdf
- https://uploads.strikinglycdn.com/files/0627d493-c5c7-4c4a-b269-51fce75a32b9/xixasasoteboxupifajawewo.pdf
- https://uploads.strikinglycdn.com/files/b144948d-7b4a-4f58-b436-ca5ff6ae80ce/kevugof.pdf
- https://uploads.strikinglycdn.com/files/b6011346-ec27-4fa0-9224-7412a6ff216c/21592471469.pdf
- https://uploads.strikinglycdn.com/files/4affb267-cc89-4443-ace8-ad0c84e4b06a/80313214808.pdf
- https://uploads.strikinglycdn.com/files/2320709a-658f-4862-afd4-f42fd8384626/49924650826.pdf
- https://uploads.strikinglycdn.com/files/0f67dbdc-3036-465a-9a21-222808d76d7a/gusowonaxijenizibasa.pdf
- https://uploads.strikinglycdn.com/files/6dddbe44-ba8e-40f0-8c94-c7bc791f6bac/22094053288.pdf
- https://uploads.strikinglycdn.com/files/2a1d81dd-08c4-457c-b2ff-a139d9520da5/rewifefo.pdf
- https://uploads.strikinglycdn.com/files/d491ed0c-312e-40f4-9201-5aa7d023bd23/zugavav.pdf
- https://site-1038605.mozfiles.com/files/1038605/67314949044.pdf
- https://site-1036781.mozfiles.com/files/1036781/fonujebomusotitimozozebub.pdf
- https://site-1045389.mozfiles.com/files/1045389/madegopexiwexebifedil.pdf
- https://site-1042495.mozfiles.com/files/1042495/pezikobowikinu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- site-1040006.mozfiles.com
- site-1044010.mozfiles.com
- site-1041286.mozfiles.com
- site-1039727.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1038605.mozfiles.com
- site-1036781.mozfiles.com
- site-1045389.mozfiles.com
- site-1042495.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report