SUSPICIOUS — 7b27ae6c2474.pdf
SUSPICIOUS — 7b27ae6c2474.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
5d3d62d2b1250ffe1bfcdb2e5112d465e959a30bf4b00f1d5a5bb10ed24c34ca - SHA-1:
d58c4d19a789c9d672d6ea0c0435374212739775 - MD5:
d6cd447a95f3cf813af74829549fb01e - ssdeep:
1536:uGFVpZjg+nILQCCriXErRexEDWlmYGP1C6R:XFVpZT8QCC20rIEDW/4v - TLSH:
T120349EF340D7EC8CB98AC7836DAB25965049C38D6136D760588C6B2CD5BC6BE7E00961 - Submitted as: 7b27ae6c2474.pdf
- File type: pdf · Size: 53454 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=circuit%20rlc%20fonction%20de%20transfert, https://uploads.strikinglycdn.com/files/54c641fd-55a8-4adf-9b47-2e3f17aaf93c/90727301955.pdf, https://uploads.strikinglycdn.com/files/a7c794f1-d503-42a8-a394-04f07d78e346/wasogumu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=circuit%20rlc%20fonction%20de%20transfert
- https://uploads.strikinglycdn.com/files/54c641fd-55a8-4adf-9b47-2e3f17aaf93c/90727301955.pdf
- https://uploads.strikinglycdn.com/files/a7c794f1-d503-42a8-a394-04f07d78e346/wasogumu.pdf
- https://uploads.strikinglycdn.com/files/fa64a14a-5fb9-4e4f-b4bd-79970a286ceb/dutuzuxozaforapinojukenur.pdf
- https://uploads.strikinglycdn.com/files/7b476847-ef8a-4d8a-8e51-fe9e6a259c47/xetadufuxedawuwi.pdf
- https://uploads.strikinglycdn.com/files/07b06747-2091-437b-afee-52fb44a8faa8/82905431613.pdf
- https://cdn.shopify.com/s/files/1/0503/5465/1294/files/22098568787.pdf
- https://cdn.shopify.com/s/files/1/0496/6223/0685/files/civil_rights_quotes_about_education.pdf
- https://cdn.shopify.com/s/files/1/0437/0730/2037/files/totes_snow_boots_dsw.pdf
- https://cdn.shopify.com/s/files/1/0430/6157/5834/files/lowes_hunter_ceiling_fans_without_lights.pdf
- https://cdn.shopify.com/s/files/1/0432/7846/7222/files/nowexevoruxopode.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/siluvilasoniz.pdf
- https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/sewesaruguji.pdf
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/wasonomibirobe.pdf
- https://cdn.shopify.com/s/files/1/0495/5255/6184/files/vegakug.pdf
- https://cdn.shopify.com/s/files/1/0433/8935/4142/files/56429811924.pdf
- https://cdn.shopify.com/s/files/1/0500/0475/4601/files/99960799322.pdf
- https://cdn.shopify.com/s/files/1/0497/2150/7997/files/covenant_marriage_gary_chapman.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/5048195.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/wurulixopif.pdf
- https://xubuvene.weebly.com/uploads/1/3/1/3/131380433/semitabiz.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/e5bcd2697.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/lopinudifegopotukas.pdf
- https://cdn.shopify.com/s/files/1/0502/1673/0799/files/romanticismo_arte_riassunto.pdf
- https://cdn.shopify.com/s/files/1/0478/8862/9926/files/comparing_two_list.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- dejolezeg.weebly.com
- jonukejunuxesa.weebly.com
- wonigebegi.weebly.com
- vilukenuxe.weebly.com
- gusumadanu.weebly.com
- xubuvene.weebly.com
- gimejexoxixaza.weebly.com
- tavumake.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report