SUSPICIOUS — 60332f47b.pdf
SUSPICIOUS — 60332f47b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
335058a6cc5db3ecdf20ebc7dc1a0ee8acea850bd1e388a1bf0d8e89113804a9 - SHA-1:
bfb79e4c71608a4d032df6adb9e03ff118c1b67d - MD5:
82b5b96700c0be5155abee7a43643701 - ssdeep:
1536:YGFjegXf6xOgkrz5aMA0LIz/edNd2lPnvEOv:1Fjeutgk/DYG3d4Rv - TLSH:
T11034AFF340ABEC8C79C6A74359E71165698AD3CC2372EB5008C87A6DC07C6BE7E50A51 - Submitted as: 60332f47b.pdf
- File type: pdf · Size: 55031 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=building%20society%20roll%20number%20format, https://cdn.shopify.com/s/files/1/0493/7187/3446/files/famerojupisix.pdf, https://cdn.shopify.com/s/files/1/0430/4361/8965/files/download_netflix_movies_on_android.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=building%20society%20roll%20number%20format
- https://cdn.shopify.com/s/files/1/0493/7187/3446/files/famerojupisix.pdf
- https://cdn.shopify.com/s/files/1/0430/4361/8965/files/download_netflix_movies_on_android.pdf
- https://cdn.shopify.com/s/files/1/0497/1560/9761/files/abercrombie_and_fitch_childrens_size_guide.pdf
- https://cdn.shopify.com/s/files/1/0432/8118/6972/files/discord_syntax_highlighting_c.pdf
- https://cdn.shopify.com/s/files/1/0496/0278/9540/files/65837774660.pdf
- https://uploads.strikinglycdn.com/files/2830c207-c81b-4210-9566-6296318c77ea/38556393406.pdf
- https://uploads.strikinglycdn.com/files/e29ed281-1220-4ed8-bda7-34ed049fca3a/zoram.pdf
- https://uploads.strikinglycdn.com/files/dde1325f-1b16-4e78-93a7-62f4cc63a3bb/fedokelaso.pdf
- https://uploads.strikinglycdn.com/files/f528e94c-e03a-4a41-a693-487b530ceb34/kelabutirukusezasud.pdf
- https://uploads.strikinglycdn.com/files/69903517-898b-4000-8e12-8a7837b80cb6/42269782511.pdf
- https://uploads.strikinglycdn.com/files/50087cab-e9f0-47e7-913f-503b10dfee09/bukepavogumokapomuzomere.pdf
- https://uploads.strikinglycdn.com/files/c127c8d4-968e-4269-a71f-87ee894d8453/rogupum.pdf
- https://uploads.strikinglycdn.com/files/9bd5ebed-136c-42c5-a425-7a7e4b07d26f/nozowuduvitimajinixobi.pdf
- https://site-1042888.mozfiles.com/files/1042888/8605478536.pdf
- https://site-1042348.mozfiles.com/files/1042348/21176595815.pdf
- https://site-1038867.mozfiles.com/files/1038867/59979791270.pdf
- https://site-1036880.mozfiles.com/files/1036880/mawibadokodaxolinem.pdf
- https://site-1042496.mozfiles.com/files/1042496/81817538139.pdf
- https://site-1036751.mozfiles.com/files/1036751/xisawufejudow.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1042888.mozfiles.com
- site-1042348.mozfiles.com
- site-1038867.mozfiles.com
- site-1036880.mozfiles.com
- site-1042496.mozfiles.com
- site-1036751.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report