SUSPICIOUS — 8959612.pdf
SUSPICIOUS — 8959612.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
733c83d48c3ba9deb239ad57ef23a2d1306737b19cf5b28fa13b7f8599fdfb60 - SHA-1:
7ceb85d0b7f39ac2a235184d7ab59e0452453f41 - MD5:
704d1595465caf5d704e164707a1ae23 - ssdeep:
768:OPgGzpD0e8XAa76S7hPOi3tyGu+CYywbL1SAYF2YXMC1POEQaXlPWVyUl:7GF4eMCmLQA82YX2EQ0lP+yUl - TLSH:
T164329EF355ABEC8C6A8BAB039DBB141A5489C7497132D790818C7B2CC07C6FE6F10951 - Submitted as: 8959612.pdf
- File type: pdf · Size: 47268 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=eigrp%20routing%20protocol%20interview%20questions%20and%20answers, https://cdn-cms.f-static.net/uploads/4367286/normal_5f8768a244aa1.pdf, https://cdn-cms.f-static.net/uploads/4367642/normal_5f8776fa98085.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=eigrp%20routing%20protocol%20interview%20questions%20and%20answers
- https://cdn-cms.f-static.net/uploads/4367286/normal_5f8768a244aa1.pdf
- https://cdn-cms.f-static.net/uploads/4367642/normal_5f8776fa98085.pdf
- https://cdn-cms.f-static.net/uploads/4367300/normal_5f8790a264487.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f86f4361cd3f.pdf
- https://cdn.shopify.com/s/files/1/0433/3276/3801/files/sazogipirodofavudelol.pdf
- https://cdn.shopify.com/s/files/1/0435/2511/1967/files/acls_manual_online.pdf
- https://cdn.shopify.com/s/files/1/0484/6203/7153/files/word_whizzle_dragon_answers_japan.pdf
- https://cdn.shopify.com/s/files/1/0482/8630/2370/files/subujexu.pdf
- https://cdn.shopify.com/s/files/1/0438/3657/1808/files/44949555178.pdf
- https://uploads.strikinglycdn.com/files/c0be9992-349e-47c2-b90d-f754cf864148/zopuligojibobo.pdf
- https://uploads.strikinglycdn.com/files/2e6d8d45-9877-4351-a38c-66586abfc0e1/18984764948.pdf
- https://uploads.strikinglycdn.com/files/2b7ad5cf-17b6-4954-b2f9-f613726b0142/jimizibozokekabevaberalu.pdf
- https://uploads.strikinglycdn.com/files/9bae1182-807c-43d0-ae8c-25aa376a6a1f/75559177608.pdf
- https://cdn.shopify.com/s/files/1/0481/3707/6887/files/xipeduzi.pdf
- https://cdn.shopify.com/s/files/1/0440/4445/1990/files/rekab.pdf
- https://uploads.strikinglycdn.com/files/205444d0-7639-4d32-95d3-58c2ab8b4791/diloz.pdf
- https://uploads.strikinglycdn.com/files/116ed984-6866-4884-80d3-6a645f6d0cb1/zulegeve.pdf
- https://uploads.strikinglycdn.com/files/6bfd10bc-530a-4319-a31d-ec15efe73ff9/90572164179.pdf
- https://uploads.strikinglycdn.com/files/26350555-a40b-47c7-a929-33125c18b500/nirabarupirisabe.pdf
- https://uploads.strikinglycdn.com/files/9bcc8cd4-d6f1-4d11-b436-2fd50bc9fc59/69364043658.pdf
- https://site-1038756.mozfiles.com/files/1038756/ramset_epcon_g5_design_guide.pdf
- https://site-1038982.mozfiles.com/files/1038982/34555076657.pdf
- https://site-1039156.mozfiles.com/files/1039156/37502732929.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1038756.mozfiles.com
- site-1038982.mozfiles.com
- site-1039156.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report