SUSPICIOUS — 7796637.pdf
SUSPICIOUS — 7796637.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
28f1867add11b4b3d09f8cd0e64a9f6e990e0ead258d22a4013e8c6b8d626c1b - SHA-1:
bd4d6d91a7fc45826b7cd4790e3e53f95fdc241d - MD5:
e43f0ecc3fee3d0f798bf47c7cca0911 - ssdeep:
768:UvgGzpDQpwwyz78qH+mrOJ/rwIP1JrWC3av7CB8Iqq3ic2O:JGFEpww9DiC3aBIqq3ic2O - TLSH:
T135305BF31097EC8C3B8FAF13AAAB11A9654AD78D60278750498C671CD5BC6ED3F00951 - Submitted as: 7796637.pdf
- File type: pdf · Size: 36046 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=design%20of%20concrete%20structures%2015th%20edition%20solutions, https://cdn.shopify.com/s/files/1/0484/0236/6632/files/13384793546.pdf, https://cdn.shopify.com/s/files/1/0437/4685/3016/files/nucleic_acid_coloring_worksheet_answers.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=design%20of%20concrete%20structures%2015th%20edition%20solutions
- https://cdn.shopify.com/s/files/1/0484/0236/6632/files/13384793546.pdf
- https://cdn.shopify.com/s/files/1/0437/4685/3016/files/nucleic_acid_coloring_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0486/0723/2158/files/johnny_the_homicidal_maniac_quotes.pdf
- https://cdn.shopify.com/s/files/1/0484/5371/4070/files/69265785820.pdf
- https://cdn.shopify.com/s/files/1/0503/9993/6662/files/echo_dot_2nd_generation_setup_instructions.pdf
- https://uploads.strikinglycdn.com/files/ccee8c4e-5238-4de0-9261-a057036154b7/63488833449.pdf
- https://uploads.strikinglycdn.com/files/eb688870-0424-439b-8108-9503e2cc6c10/modibaxaked.pdf
- https://uploads.strikinglycdn.com/files/c6c666cb-ab37-4f28-a034-982bab4db32b/93605054378.pdf
- https://uploads.strikinglycdn.com/files/0157d0d7-9876-4662-b976-4b227e4304c8/25245197736.pdf
- https://uploads.strikinglycdn.com/files/da88b4ee-982a-4a20-a29e-2ddc5297fc0b/75436912728.pdf
- https://uploads.strikinglycdn.com/files/f8f7faee-a5a8-4187-8767-24a2bb40deec/mosque_de_cordoue_histoire_des_arts.pdf
- https://uploads.strikinglycdn.com/files/475b20a5-288d-4cb3-b5e6-7585436d0de1/jatagaxotobulufesevak.pdf
- https://uploads.strikinglycdn.com/files/07c41425-6647-42e9-9df4-eac497ff6e5c/12485855032.pdf
- https://uploads.strikinglycdn.com/files/169af75e-a675-4d8f-9c0d-55a3e931f4f0/54358321627.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/gazolitizujavimowe.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/6051869.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/birozalulup-gojarubag-regobagediz-bepiza.pdf
- https://rozazokosu.weebly.com/uploads/1/3/0/8/130813972/165573.pdf
- https://lotagixowila.weebly.com/uploads/1/3/1/1/131164100/vinebev.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87b4f823ce7.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f875b75b66c0.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8816391e804.pdf
- https://cdn-cms.f-static.net/uploads/4369173/normal_5f88efefdf7d9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- vozunutav.weebly.com
- lodirunesu.weebly.com
- juragubiv.weebly.com
- rozazokosu.weebly.com
- lotagixowila.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report