SUSPICIOUS — 90167449217.pdf
SUSPICIOUS — 90167449217.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5d140b438bdf82eebef39b37a0ed82dbeed90812009f5856ddcd623fb7182248 - SHA-1:
559ed19d09c47ac9435eaac3a6ed86bdad24b99a - MD5:
b0cfd5a53dc77887ff250031f53e9739 - ssdeep:
3072:5FAAJjYTFq940WdaQA8XKO1Nx20SDqmpelkDPNc2rCfOKLP05KyWLhQX:fhjd40Wda2D7mpel4H2Rty - TLSH:
T1E64212F387D7DD8C92458B03EDAA1507626955891563AF6862EC2BACC83C3FE3D10E41 - Submitted as: 90167449217.pdf
- File type: pdf · Size: 204955 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=infarctus+myocarde+pdf, https://cdn.shopify.com/s/files/1/0433/3695/8106/files/the_jungle_book_boy_video.pdf, https://cdn.shopify.com/s/files/1/0438/2552/8989/files/tafewogarosabef.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=infarctus+myocarde+pdf
- https://cdn.shopify.com/s/files/1/0433/3695/8106/files/the_jungle_book_boy_video.pdf
- https://cdn.shopify.com/s/files/1/0438/2552/8989/files/tafewogarosabef.pdf
- https://cdn.shopify.com/s/files/1/0485/3189/8523/files/estilo_de_vida_saludable_en_el_trabajo.pdf
- http://files.bridgetghunt.com/uploads/1/3/1/4/131483154/3425382.pdf
- http://files.periodswithpride.org/uploads/1/3/0/8/130814594/febudamosedelobaziro.pdf
- http://tozakone.stackastory.org/uploads/1/3/1/3/131380600/xezepazobon.pdf
- http://zoximigi.healthychocoholic.com/uploads/1/3/0/7/130739206/882f068.pdf
- http://files.ofwrealestate.com/uploads/1/3/1/4/131437194/117135786a3.pdf
- http://files.oneglobaldekalb.org/uploads/1/3/1/4/131409717/9673804.pdf
- http://matekajig.supportedimmersion.com/uploads/1/3/1/3/131379803/1838432.pdf
- http://xunogazid.deniskilcommons.com/uploads/1/3/1/3/131398285/3367318.pdf
- http://files.firrunnursery.com/uploads/1/3/0/7/130738915/jabegeno-nuganoroxeweja.pdf
- https://cdn.shopify.com/s/files/1/0484/8530/2433/files/to_kill_a_mockingbird_final_test_questions_and_answers.pdf
- https://cdn.shopify.com/s/files/1/0437/8561/7566/files/power_of_attorney_revocation_form_california.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- files.bridgetghunt.com
- files.periodswithpride.org
- tozakone.stackastory.org
- zoximigi.healthychocoholic.com
- files.ofwrealestate.com
- files.oneglobaldekalb.org
- matekajig.supportedimmersion.com
- xunogazid.deniskilcommons.com
- files.firrunnursery.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report