SUSPICIOUS — 9668621.pdf
SUSPICIOUS — 9668621.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
98d81fc7b6f901dc53faebae43e10d9bb2b93821d0634d92b9e230dafdfdd0ec - SHA-1:
4956b635c7f2bb99536f573bb2e4db601a12a32e - MD5:
92d839aa612147936929eed375bee90b - ssdeep:
768:ngGzpDbpIh2qno7XAYlo8grlK/OdZVhs5mgRaH+gfOvbx:gGFvpNo6/CV8mgIH+gmvbx - TLSH:
T1DB306CF34097ED8C7A8F9F03AEAB155D414EC38D613A96501588772CE07CAAD7E10EA1 - Submitted as: 9668621.pdf
- File type: pdf · Size: 37435 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=excel%20for%20dummies%20pdf%202013, https://uploads.strikinglycdn.com/files/12cc46f6-d58b-4fb5-9bd2-c797b8c7facc/docker_book.pdf, https://uploads.strikinglycdn.com/files/76a2bef4-8292-4011-87e3-6bb1754d2eb7/kewegotewavefeperovaxosiv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=excel%20for%20dummies%20pdf%202013
- https://uploads.strikinglycdn.com/files/12cc46f6-d58b-4fb5-9bd2-c797b8c7facc/docker_book.pdf
- https://uploads.strikinglycdn.com/files/76a2bef4-8292-4011-87e3-6bb1754d2eb7/kewegotewavefeperovaxosiv.pdf
- https://uploads.strikinglycdn.com/files/c29c652c-7692-425b-986b-a9effeb05fd0/amd_radeon_hd_7400m_driver_windows_10.pdf
- https://uploads.strikinglycdn.com/files/16ba4323-c671-4c1b-b5cd-0a2d043eb731/70955956584.pdf
- https://uploads.strikinglycdn.com/files/40a4d65a-2a33-4a36-92ac-8bb5b200986f/30504154437.pdf
- https://s3.amazonaws.com/jifesu/50983422992.pdf
- https://s3.amazonaws.com/sevoga/28816632449.pdf
- https://s3.amazonaws.com/didowugorokirug/96407473220.pdf
- https://s3.amazonaws.com/mefovu/burner_management_system_in_boiler.pdf
- https://s3.amazonaws.com/luramamelolem/xawenidobovodisuba.pdf
- https://uploads.strikinglycdn.com/files/b2906ee8-6b7b-4c27-8f4a-b7fbe688cebc/amplitud_y_periodo_de_las_funciones_trigonometricas.pdf
- https://uploads.strikinglycdn.com/files/af133b0b-63b8-40ee-b819-b5dbaba4dc3a/lexogopabuwupofolosavug.pdf
- https://uploads.strikinglycdn.com/files/eba3ed75-e0b7-4a1b-8541-7cf620170ff5/97268787499.pdf
- https://uploads.strikinglycdn.com/files/2f81546b-9cd9-4a28-bc7f-a57f325399cc/out_of_sync_child_has_fun.pdf
- https://s3.amazonaws.com/xuzed/folifefexogeja.pdf
- https://s3.amazonaws.com/sinamozagemoger/aswath_damodaran_the_dark_side_of_valuation.pdf
- https://cdn.shopify.com/s/files/1/0484/3369/2830/files/21388750370.pdf
- https://cdn.shopify.com/s/files/1/0428/8882/2950/files/23051301300.pdf
- https://cdn.shopify.com/s/files/1/0436/2135/1587/files/android_read_file_from_root_directory.pdf
- https://cdn.shopify.com/s/files/1/0437/1048/0533/files/bizotitodaj.pdf
- https://uploads.strikinglycdn.com/files/5d8562cf-464b-4c67-bae5-4b361a10ce32/34834633831.pdf
- https://uploads.strikinglycdn.com/files/2cff87ce-c9a4-4e2a-91dc-12324a1aa7f9/classical_guitar_amplification.pdf
- https://uploads.strikinglycdn.com/files/11382abf-8eb5-485b-af6c-2b6beeb75910/toveduse.pdf
- https://uploads.strikinglycdn.com/files/24d7fc6a-1129-4150-ab0a-83daee01d297/3288493127.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report