SUSPICIOUS — ee9fff79f5f.pdf
SUSPICIOUS — ee9fff79f5f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
91031118cd720cb6f243d82fad65b6649cc5bbd1069991e038ec906b0fe2a961 - SHA-1:
691d37498b775c5b6d8dc994fda93b4a6b5b1d1b - MD5:
0a1ac7252da14165318b5040bbfb1850 - ssdeep:
1536:cGF2p43dhKP9zkkBjSOhjt4/MDP/Ldde9vagi+agSTJ:5F2pqdvojrjt4/MDP/Lddehagjk - TLSH:
T10634BFF75457DD4C7A8FAB03AEAA01A8948BC38D602297A008CC771DD47CAFD7E50952 - Submitted as: ee9fff79f5f.pdf
- File type: pdf · Size: 55861 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%2012%20basic%20functions, https://uploads.strikinglycdn.com/files/9b113c62-4b48-4251-a586-ae65c8438dd0/21486395491.pdf, https://uploads.strikinglycdn.com/files/37079b18-b33c-4336-b71c-a8fe0d00791a/kuwalitepediwim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%2012%20basic%20functions
- https://uploads.strikinglycdn.com/files/9b113c62-4b48-4251-a586-ae65c8438dd0/21486395491.pdf
- https://uploads.strikinglycdn.com/files/37079b18-b33c-4336-b71c-a8fe0d00791a/kuwalitepediwim.pdf
- https://uploads.strikinglycdn.com/files/254c1b8b-bd57-4075-9649-2c7368345eb0/97793102159.pdf
- https://cdn.shopify.com/s/files/1/0488/3336/4133/files/84423476826.pdf
- https://cdn.shopify.com/s/files/1/0484/7897/8210/files/67099274161.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f874e1cf404d.pdf
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f881714a72f9.pdf
- https://cdn-cms.f-static.net/uploads/4369923/normal_5f880259148ba.pdf
- https://cdn-cms.f-static.net/uploads/4368477/normal_5f87fb831331a.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f878b7b1fc50.pdf
- https://cdn.shopify.com/s/files/1/0484/3051/4330/files/peg_medical_abbreviation.pdf
- https://cdn.shopify.com/s/files/1/0482/2056/9752/files/1897686176.pdf
- https://cdn.shopify.com/s/files/1/0434/4872/9767/files/74204448223.pdf
- https://cdn-cms.f-static.net/uploads/4366395/normal_5f8756be1cc7e.pdf
- https://cdn-cms.f-static.net/uploads/4369631/normal_5f8819ef74d5c.pdf
- https://cdn-cms.f-static.net/uploads/4366623/normal_5f8732d7a91e6.pdf
- https://cdn-cms.f-static.net/uploads/4368478/normal_5f87fe0e307e7.pdf
- https://site-1038530.mozfiles.com/files/1038530/tiramujuwuvubomogom.pdf
- https://site-1037235.mozfiles.com/files/1037235/57046177701.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1038530.mozfiles.com
- site-1037235.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report