SUSPICIOUS — b53f7350640258f.pdf
SUSPICIOUS — b53f7350640258f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6b7e4db90cdb1f6c249b040b4ec2748538798cce05258d14b3c7ba3935f2d209 - SHA-1:
83069e301527be67c4dfb6c4bfb2bf7c7059be9e - MD5:
6d495b7c4e0e0c6237d97dc9b033973e - ssdeep:
768:igGzpD7pVHT/jehLvCzXjePziG7jLHbhCaKiAby4IIbKP50XHifoR6upUoGq1o/+:/GFnpVq7X78akXIGKPkHpJOtq1o/+ - TLSH:
T15F328DF350A7DC8C7E878B43ADAA14699589D34C6137EBA01588772CC0BC27D6E10961 - Submitted as: b53f7350640258f.pdf
- File type: pdf · Size: 43749 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20twelve%20days%20of%20christmas%20chords%20pdf, https://cdn-cms.f-static.net/uploads/4368742/normal_5f88ee9893135.pdf, https://cdn-cms.f-static.net/uploads/4376875/normal_5f93d8fda56a9.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20twelve%20days%20of%20christmas%20chords%20pdf
- https://cdn-cms.f-static.net/uploads/4368742/normal_5f88ee9893135.pdf
- https://cdn-cms.f-static.net/uploads/4376875/normal_5f93d8fda56a9.pdf
- https://cdn-cms.f-static.net/uploads/4378853/normal_5f90e6d620822.pdf
- https://uploads.strikinglycdn.com/files/bf0599e6-bcbf-4a8c-a233-a9ac756399f1/govenudu.pdf
- https://uploads.strikinglycdn.com/files/d1b5a502-d3b3-4cea-9a07-cf849144827b/65485098690.pdf
- https://uploads.strikinglycdn.com/files/7d2cc748-43ef-4931-a687-7b28600820cb/43686381264.pdf
- https://cdn.shopify.com/s/files/1/0434/4279/8757/files/xoradisa.pdf
- https://cdn.shopify.com/s/files/1/0481/8396/7896/files/case_conceptualization_example.pdf
- https://cdn.shopify.com/s/files/1/0266/9530/3355/files/moditarijonuzuripoxajusa.pdf
- https://cdn.shopify.com/s/files/1/0484/8392/6171/files/app_to_fix_red_eye_android.pdf
- https://s3.amazonaws.com/wisuw/economist_july.pdf
- https://s3.amazonaws.com/tobojelusiwi/mastering_algorithms_with_c_free.pdf
- https://s3.amazonaws.com/lixuduwonifa/xefiligamak.pdf
- https://s3.amazonaws.com/fowikorejodi/asme_a17-_1.pdf
- https://cdn.shopify.com/s/files/1/0432/1558/5448/files/rereworubaxatarut.pdf
- https://cdn.shopify.com/s/files/1/0496/3922/7543/files/28508608731.pdf
- https://cdn.shopify.com/s/files/1/0480/7242/5636/files/how_to_play_othello.pdf
- https://cdn.shopify.com/s/files/1/0500/7258/4380/files/revelation_song_chords.pdf
- https://cdn.shopify.com/s/files/1/0478/0651/3311/files/gilavimufuvanesovit.pdf
- https://s3.amazonaws.com/mijedusovineti/81583954262.pdf
- https://s3.amazonaws.com/xanebavifamopez/bluebells_of_scotland_trombone.pdf
- https://s3.amazonaws.com/potofaw/best_self_self_journal.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report