SUSPICIOUS — 37c2f85c.pdf
SUSPICIOUS — 37c2f85c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2a8aff371c115bb5041ac609c657dc6aafdffd3e84285b5a5733ec6f6f33a16a - SHA-1:
b3127375f314fddc55257b727228cbb5dd00e2cf - MD5:
e12cbe9a0cfce6be1ab3cc5f98fc3726 - ssdeep:
768:OgGzpDlpQ0/3PsxUNnZV9olHRqmN0edRmMKtbZ:rGFBp3V9olHnd0MKtbZ - TLSH:
T12C304BF34093ED8C7A8FAF43AEEB11995189D68D622297500488773CD47CABD3F10A61 - Submitted as: 37c2f85c.pdf
- File type: pdf · Size: 39180 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=marcin%20chojecki%20basf%20las%20sustancias, https://site-1038407.mozfiles.com/files/1038407/kitivolanaxojawewip.pdf, https://site-1036932.mozfiles.com/files/1036932/95119017137.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=marcin%20chojecki%20basf%20las%20sustancias
- https://site-1038407.mozfiles.com/files/1038407/kitivolanaxojawewip.pdf
- https://site-1036932.mozfiles.com/files/1036932/95119017137.pdf
- https://site-1044103.mozfiles.com/files/1044103/mogorafefawasi.pdf
- https://site-1039430.mozfiles.com/files/1039430/moxumosiloberufed.pdf
- https://site-1040360.mozfiles.com/files/1040360/sefezemijosisexe.pdf
- https://site-1038963.mozfiles.com/files/1038963/21544695073.pdf
- https://site-1039959.mozfiles.com/files/1039959/zodedibibajixez.pdf
- https://wovasemuzusalej.weebly.com/uploads/1/3/1/6/131636629/gefurilelitidorexe.pdf
- https://xirofepomare.weebly.com/uploads/1/3/0/8/130814083/fijopunidivarejesuje.pdf
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/bbb9cb4a.pdf
- https://xubuvene.weebly.com/uploads/1/3/1/3/131380433/382aef3a93439.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/3250b5961ed1.pdf
- https://cdn.shopify.com/s/files/1/0437/5055/5799/files/pink_depression_glass_cake_platter.pdf
- https://cdn.shopify.com/s/files/1/0480/2812/3295/files/pefalafatemunaremove.pdf
- https://cdn.shopify.com/s/files/1/0498/0064/2721/files/yo_ho_ho.io_crazy_games.pdf
- https://cdn.shopify.com/s/files/1/0495/6644/9816/files/samsung_smt_h3362_manual.pdf
- https://cdn.shopify.com/s/files/1/0431/9051/7917/files/middle_school_story_ideas.pdf
- https://site-1043205.mozfiles.com/files/1043205/nazuxolorineloxukixokoze.pdf
- https://site-1043442.mozfiles.com/files/1043442/72450792170.pdf
- https://site-1042432.mozfiles.com/files/1042432/boxifor.pdf
- https://site-1043793.mozfiles.com/files/1043793/xexilavo.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/timufitu.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- site-1038407.mozfiles.com
- site-1036932.mozfiles.com
- site-1044103.mozfiles.com
- site-1039430.mozfiles.com
- site-1040360.mozfiles.com
- site-1038963.mozfiles.com
- site-1039959.mozfiles.com
- wovasemuzusalej.weebly.com
- xirofepomare.weebly.com
- biwugina.weebly.com
- xubuvene.weebly.com
- mojivimimujovo.weebly.com
- cdn.shopify.com
- site-1043205.mozfiles.com
- site-1043442.mozfiles.com
- site-1042432.mozfiles.com
- site-1043793.mozfiles.com
- megadezatesaram.weebly.com
- vuxozajuje.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report