SUSPICIOUS — 5734308.pdf
SUSPICIOUS — 5734308.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7fa25a646f4da8608eddf925810c3114408ea49753df037e4b62e2d4ac8a4ca6 - SHA-1:
12bc9f2ab4aa565604e437ef8ce6a51c81f0eae2 - MD5:
62a24aa24d275c509aee82c39485acb9 - ssdeep:
768:zgGzpDrpgISSqTtWZnahl6vXOdUGlcyMHC2v4LVjEKyTVCHWquCv9Am3Zqud:MGFvpbGyyJ2vAAVCHWwv9Am3Zqud - TLSH:
T137338DF35063ED5C3ACB9B83ADBA15587045D68A6123A69005CC7B2CC17C6EDBF41A31 - Submitted as: 5734308.pdf
- File type: pdf · Size: 49875 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=biblia%20de%20estudio%20thompson%20gratis%20en%20espa%25C3%25B1ol, https://cdn.shopify.com/s/files/1/0431/4939/4080/files/which_of_the_following_accounts_impact_equity_check_all_that_apply.pdf, https://cdn.shopify.com/s/files/1/0497/9297/5011/files/92606434929.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=biblia%20de%20estudio%20thompson%20gratis%20en%20espa%25C3%25B1ol
- https://cdn.shopify.com/s/files/1/0431/4939/4080/files/which_of_the_following_accounts_impact_equity_check_all_that_apply.pdf
- https://cdn.shopify.com/s/files/1/0497/9297/5011/files/92606434929.pdf
- https://cdn.shopify.com/s/files/1/0429/5737/3589/files/funny_community_service_quotes.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/4040610.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/fawinikaraba.pdf
- https://xonuguzuv.weebly.com/uploads/1/3/1/3/131382030/b43f30.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/7583260.pdf
- https://site-1040250.mozfiles.com/files/1040250/nawaxetatasutinogodovabe.pdf
- https://site-1037202.mozfiles.com/files/1037202/guwedixudof.pdf
- https://site-1040286.mozfiles.com/files/1040286/72970037988.pdf
- https://site-1038416.mozfiles.com/files/1038416/detarorugalivolibadogeler.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f86fce0ea988.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f8734d9e5eeb.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f8739b66c985.pdf
- https://cdn.shopify.com/s/files/1/0497/4703/4266/files/iowa_high_school_wrestling_tournament_2020_schedule.pdf
- https://cdn.shopify.com/s/files/1/0431/3192/8730/files/15144639525.pdf
- https://cdn.shopify.com/s/files/1/0438/4499/3181/files/sefamulegalagakaginit.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f875dee11e9b.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f870351b8024.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- zoveponezewuda.weebly.com
- sibakixode.weebly.com
- xonuguzuv.weebly.com
- sepikupi.weebly.com
- site-1040250.mozfiles.com
- site-1037202.mozfiles.com
- site-1040286.mozfiles.com
- site-1038416.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report