SUSPICIOUS — 4407951.pdf
SUSPICIOUS — 4407951.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
8bdac087dcf5e6d860b2eb1aa67e38dff8e5652954329a8e4e2696feafaef079 - SHA-1:
837a68e8301803a8e6245d946bae6ce7cd53e29a - MD5:
7cd4afe0c1916f3ba8e2059bca08940f - ssdeep:
768:8gGzpDtpN2kPLQoDxVplwd2eorUUyGTALfpSCv83ThA7z5hKqePeV+sT+O:ZGFBpNuwypnv8DSDKqZ+sT+O - TLSH:
T147326BF351A7ED4C3AC7DF036DEE252DA089DB486232979084996B2CC57C3BC2E50961 - Submitted as: 4407951.pdf
- File type: pdf · Size: 43935 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=mugen%20full%20game, https://cdn.shopify.com/s/files/1/0483/3227/5865/files/poker_offline_mod_apk_latest_version.pdf, https://cdn.shopify.com/s/files/1/0428/9629/4051/files/sutubadibaruxapumowup.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=mugen%20full%20game
- https://cdn.shopify.com/s/files/1/0434/8048/1954/files/xerokijugoka.pdf
- https://cdn.shopify.com/s/files/1/0483/3227/5865/files/poker_offline_mod_apk_latest_version.pdf
- https://cdn.shopify.com/s/files/1/0428/9629/4051/files/sutubadibaruxapumowup.pdf
- https://cdn.shopify.com/s/files/1/0479/5993/3095/files/folilebegiguzifetidimijov.pdf
- https://cdn.shopify.com/s/files/1/0435/9038/5823/files/fast_lyrics_sueco_remix.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f878b2219a8a.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8786731f598.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f87524a4698b.pdf
- https://cdn-cms.f-static.net/uploads/4366358/normal_5f87a54008df7.pdf
- https://cdn-cms.f-static.net/uploads/4370088/normal_5f87fa1aa498e.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f873423c82ae.pdf
- https://cdn-cms.f-static.net/uploads/4369153/normal_5f8805d29325c.pdf
- https://cdn-cms.f-static.net/uploads/4369174/normal_5f87fcbf54e0d.pdf
- https://uploads.strikinglycdn.com/files/885404a6-035f-45b9-b3e9-71d2d5f25b6e/revuzomasogav.pdf
- https://uploads.strikinglycdn.com/files/4bcfebe9-6803-4777-8d49-960a24a82fd1/riworudoxesegadajena.pdf
- https://uploads.strikinglycdn.com/files/9e46d3fc-6574-4f9a-9bfa-88cd86b6b0f1/17427115251.pdf
- https://uploads.strikinglycdn.com/files/b026d0a4-af37-4d48-b2ac-c962c9b43268/31927237348.pdf
- https://site-1036728.mozfiles.com/files/1036728/774584383.pdf
- https://site-1038949.mozfiles.com/files/1038949/38897491889.pdf
- https://site-1040000.mozfiles.com/files/1040000/48076359359.pdf
- https://site-1036746.mozfiles.com/files/1036746/15192676124.pdf
- https://cdn.shopify.com/s/files/1/0495/6530/2936/files/best_soundcards_for_pc.pdf
- https://cdn.shopify.com/s/files/1/0496/7763/1647/files/how_do_organisms_compete_for_abiotic_factors.pdf
- https://cdn.shopify.com/s/files/1/0440/8583/7989/files/scan_qr_code_app_android.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1036728.mozfiles.com
- site-1038949.mozfiles.com
- site-1040000.mozfiles.com
- site-1036746.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report