SUSPICIOUS — b3966e5b09f03ac.pdf
SUSPICIOUS — b3966e5b09f03ac.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
79bc0cd3905c598395c6cca379278814b749ee91c5818749f4a1cf20f72ef5f9 - SHA-1:
788531367c31c6fe9ab7b10e1189abd1da3e30d9 - MD5:
fd572d5bd31bda99612f4cfffdbbd6d7 - ssdeep:
1536:kGFwpR1BwCCnpzm64u2yiUmSde12DkWhGdJI:xFwpt0pzm6+mM1iM0 - TLSH:
T17E348DF311A7DE4DBA879F43A8BB26695089C38D623297A00588776CC47C27DBF11921 - Submitted as: b3966e5b09f03ac.pdf
- File type: pdf · Size: 53168 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=dinosaurios%20para%20colorear, https://cdn.shopify.com/s/files/1/0268/7257/8218/files/23894585374.pdf, https://cdn.shopify.com/s/files/1/0496/0583/6964/files/10_speed_bike_walmart.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=dinosaurios%20para%20colorear
- https://cdn.shopify.com/s/files/1/0268/7257/8218/files/23894585374.pdf
- https://cdn.shopify.com/s/files/1/0496/0583/6964/files/10_speed_bike_walmart.pdf
- https://cdn.shopify.com/s/files/1/0434/1461/8277/files/duvatesi.pdf
- https://cdn.shopify.com/s/files/1/0437/8515/8813/files/rotibifitevolusi.pdf
- https://cdn.shopify.com/s/files/1/0481/3520/9127/files/sieve_tube_elements_structure.pdf
- https://site-1044238.mozfiles.com/files/1044238/34998753032.pdf
- https://site-1043374.mozfiles.com/files/1043374/wexofasovadimiput.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f88201a0021f.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f8801405286b.pdf
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f87ccf479967.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f8808a2c972e.pdf
- https://cdn-cms.f-static.net/uploads/4367919/normal_5f876ffbb898e.pdf
- https://site-1040002.mozfiles.com/files/1040002/16588610612.pdf
- https://site-1040100.mozfiles.com/files/1040100/ritirotogeva.pdf
- https://site-1040617.mozfiles.com/files/1040617/24686882225.pdf
- https://site-1039688.mozfiles.com/files/1039688/29284511563.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f870a613e7bc.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f87f6b83be41.pdf
- https://cdn-cms.f-static.net/uploads/4368740/normal_5f87ea2a59cd8.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/pasex.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/cf0cd7ac.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/bawap.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279037.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/3373854.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1044238.mozfiles.com
- site-1043374.mozfiles.com
- cdn-cms.f-static.net
- site-1040002.mozfiles.com
- site-1040100.mozfiles.com
- site-1040617.mozfiles.com
- site-1039688.mozfiles.com
- gusumadanu.weebly.com
- xojisige.weebly.com
- jatorogerujew.weebly.com
- fijojonibiw.weebly.com
- xojerajap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report