SUSPICIOUS — 3962734.pdf
SUSPICIOUS — 3962734.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
45f74630b8f5e225e3d9c89c5c530e3b66f30c8822d140b05e5a9fad0467c058 - SHA-1:
37ca2d2910da64e53b453b9d1968cd4a08ef9671 - MD5:
ddf8c8a570a6ae92c0f4da9463b7405b - ssdeep:
1536:KGFiLGUiKkVTPy6qrHtqegcK/aKd1HbJDW/gyTyt:zFi+Kp6CHoxcKCKfHdI0 - TLSH:
T1EB37BEF350A7ED8C7A8BDB835AE6155D6089D788B171AAA440DC763CC07C3BD6F00A61 - Submitted as: 3962734.pdf
- File type: pdf · Size: 71005 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=decluttering%20at%20the%20speed%20of%20life%20pdf, https://wopuremob.weebly.com/uploads/1/3/2/6/132696580/8e257142b.pdf, https://uploads.strikinglycdn.com/files/22599f12-ad73-46d4-b55c-dba320b3185c/56899143224.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=decluttering%20at%20the%20speed%20of%20life%20pdf
- https://s3.amazonaws.com/muvojugejoxip/fisica_capacitores_exercicios_resolvidos.pdf
- https://s3.amazonaws.com/tadovu/megupavowatavetupokit.pdf
- https://s3.amazonaws.com/jamokaroxoj/apresolina_50_mg_bula.pdf
- https://s3.amazonaws.com/zuxadol/personal_pronouns_worksheet_grade_4.pdf
- https://s3.amazonaws.com/memul/89553938925.pdf
- https://wopuremob.weebly.com/uploads/1/3/2/6/132696580/8e257142b.pdf
- https://s3.amazonaws.com/gupuso/73896745885.pdf
- https://s3.amazonaws.com/gupuso/fernando_pessoa_poems_in_english.pdf
- https://s3.amazonaws.com/pazifetanegapu/87904655124.pdf
- https://s3.amazonaws.com/pazifetanegapu/384685878.pdf
- https://s3.amazonaws.com/xanebavifamopez/75868669127.pdf
- https://uploads.strikinglycdn.com/files/22599f12-ad73-46d4-b55c-dba320b3185c/56899143224.pdf
- https://uploads.strikinglycdn.com/files/564576db-6e57-4260-a098-849cda7d34f2/74937564901.pdf
- https://uploads.strikinglycdn.com/files/4a4171d1-8ad4-47aa-b4ce-8d2f3559f01a/six_sassy_sentences.pdf
- https://uploads.strikinglycdn.com/files/ac4c2363-fdeb-4ba5-9c25-66d85ca4ade8/61526013948.pdf
- https://uploads.strikinglycdn.com/files/c453d03d-6d41-425d-8cd9-63b327ce24e5/xutak.pdf
- https://mebagotu.weebly.com/uploads/1/3/4/4/134444887/a1f92f6697.pdf
- https://sesorefamasupuv.weebly.com/uploads/1/3/1/0/131071262/4493281.pdf
- https://cdn.shopify.com/s/files/1/0504/4410/7950/files/hasselblad_x1d_user_manual.pdf
- https://cdn.shopify.com/s/files/1/0484/6629/6986/files/symphony_of_the_night_100_guide.pdf
- https://cdn.shopify.com/s/files/1/0502/2439/8528/files/tommy_hilfiger_ladies_size_guide.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- wopuremob.weebly.com
- uploads.strikinglycdn.com
- mebagotu.weebly.com
- sesorefamasupuv.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report