SUSPICIOUS — 8875438.pdf
SUSPICIOUS — 8875438.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5bc95e36646fdb5a07c8fb473b4e5318de5f6ccd86580d0fd33ac398f3cd619d - SHA-1:
25b561b68261190ea6cfc86771b92b9c50827085 - MD5:
b428ecd557f308efbc5a3c53552a9f30 - ssdeep:
768:2gGzpDkEqgaLL7OOEG0YXk2CXQG0yCXRERIgzgafOKkPaJ5:jGFwR1bEGGfCXRDrKkPaJ5 - TLSH:
T1F831AFF7A1A7DD446AC6BF035BFA15542186C78D7033E16459C93B6DC8BC2ADAE00860 - Submitted as: 8875438.pdf
- File type: pdf · Size: 39817 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=capitalismo%20y%20socialismo%20diferencias%20pdf, https://cdn-cms.f-static.net/uploads/4369168/normal_5f99eba8adc2f.pdf, https://cdn.shopify.com/s/files/1/0505/9100/6888/files/a_love_to_last_lyrics.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=capitalismo%20y%20socialismo%20diferencias%20pdf
- https://cdn-cms.f-static.net/uploads/4369168/normal_5f99eba8adc2f.pdf
- https://cdn.shopify.com/s/files/1/0505/9100/6888/files/a_love_to_last_lyrics.pdf
- https://uploads.strikinglycdn.com/files/b55cd7c6-3d20-480e-be7e-d27deed46a76/15921313496.pdf
- https://uploads.strikinglycdn.com/files/fe8d1703-853e-49f8-bbd4-55ccb68830fd/fesotiz.pdf
- https://s3.amazonaws.com/felasorarabipis/acca_f2_revision_kit.pdf
- https://uploads.strikinglycdn.com/files/f1055734-6fdf-4e37-9267-dd5e9d32aeac/pluralsight_offline_player_file_location.pdf
- https://uploads.strikinglycdn.com/files/3c5b29c1-a87e-4696-ad4d-610fe7c232fe/zopatidawigoropuperaw.pdf
- https://cdn.shopify.com/s/files/1/0502/8551/0820/files/plan_for_every_part_example.pdf
- https://uploads.strikinglycdn.com/files/99c6d9bb-d3eb-450b-955b-18472a2bd3b4/sokuxafan.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report