SUSPICIOUS — 7441641.pdf
SUSPICIOUS — 7441641.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4b876e6867387c505d133e49c8689245aa4cfad4e5319fd5518f6468002d4a11 - SHA-1:
711dbb94f297a08b345a9481d9cba1f53bad6f7f - MD5:
6061ad4c351e172a821d022db99ae580 - ssdeep:
768:3gGzpDK5GveOAYyF7GqEp+amQpi2Id5mmcj/RsSrj6:QGFGrcqEpLmLtctsSrj6 - TLSH:
T1EB319FF79057DC4C7A86AB03AE76145DB04AD7C87132A7A014C8773CC4BC6ED6E10A61 - Submitted as: 7441641.pdf
- File type: pdf · Size: 40529 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=aera%202020%20conference%20theme, https://cdn-cms.f-static.net/uploads/4384308/normal_5f8e4029b979b.pdf, https://cdn-cms.f-static.net/uploads/4390051/normal_5f96167bdbe21.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=aera%202020%20conference%20theme
- https://cdn-cms.f-static.net/uploads/4384308/normal_5f8e4029b979b.pdf
- https://cdn-cms.f-static.net/uploads/4390051/normal_5f96167bdbe21.pdf
- https://s3.amazonaws.com/fezenur/audit_report_sample.pdf
- https://cdn-cms.f-static.net/uploads/4443574/normal_5f9c9fc820b7f.pdf
- https://uploads.strikinglycdn.com/files/ea3e0793-1be2-4738-aa2f-40ffbe405400/kogevumoxuromeziv.pdf
- https://uploads.strikinglycdn.com/files/4a3bff81-d6b4-46f0-9228-89f3f0e5cdc3/22083787091.pdf
- https://uploads.strikinglycdn.com/files/161b0585-315b-44cf-b072-63e4dac338f2/af_sosyoloji_sosyal_politika_ders_notlar.pdf
- https://s3.amazonaws.com/gupuso/toladiv.pdf
- https://s3.amazonaws.com/wibedubosateg/agregado_fino_definicion.pdf
- https://cdn-cms.f-static.net/uploads/4370273/normal_5f8e947bb6945.pdf
- https://uploads.strikinglycdn.com/files/877abf87-fe3b-494c-b5ed-5e346fd59a2e/86910515950.pdf
- https://uploads.strikinglycdn.com/files/e12e0451-95eb-4c48-ba84-7a19f0dd13af/82794049966.pdf
- https://uploads.strikinglycdn.com/files/c79fbc61-8166-42d1-bc81-4f77693d09ca/80161576856.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report