SUSPICIOUS — 856e471b86a49.pdf
SUSPICIOUS — 856e471b86a49.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9f331d3a00e2885c191c626f941066b1ff2bc5516237c4346c053bd041ad4433 - SHA-1:
10148a5a6b0c5bd9bc93f35db16431ce5e6347e2 - MD5:
3e6ee2266575703e5b06d61f8e287a91 - ssdeep:
768:YgGzpDrpq7qMt6+UvCSwcn32NO9hSmqf2nMUHcY5jJQyi/orreEokX5wVC85:1GFvpamW+FlJQCr3okX+VC85 - TLSH:
T15C327CF30093ED8C7A8E5F13ADDA159DA045D38CA136D7A0459C772CD4BC9AE7E00A26 - Submitted as: 856e471b86a49.pdf
- File type: pdf · Size: 44901 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=interjection%20worksheet%20for%20class%205, https://site-1042548.mozfiles.com/files/1042548/bifewubebu.pdf, https://site-1036637.mozfiles.com/files/1036637/xomulow.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=interjection%20worksheet%20for%20class%205
- https://site-1042548.mozfiles.com/files/1042548/bifewubebu.pdf
- https://site-1036637.mozfiles.com/files/1036637/xomulow.pdf
- https://site-1044148.mozfiles.com/files/1044148/o_imperialismo_hector_bruit.pdf
- https://site-1042509.mozfiles.com/files/1042509/jekidedevefufinovixozit.pdf
- https://site-1039173.mozfiles.com/files/1039173/8771782241.pdf
- https://site-1041086.mozfiles.com/files/1041086/texixifuwivum.pdf
- https://site-1041291.mozfiles.com/files/1041291/pafalupexisezil.pdf
- https://site-1048535.mozfiles.com/files/1048535/13668247160.pdf
- https://cdn.shopify.com/s/files/1/0437/4318/2999/files/hungry_shark_world_hack_apk_download_ios.pdf
- https://cdn.shopify.com/s/files/1/0436/1335/6194/files/strawberry_shortcake_berry_happy_home_stickers.pdf
- https://cdn.shopify.com/s/files/1/0485/1279/4786/files/sound_answers_class_8.pdf
- https://cdn.shopify.com/s/files/1/0480/0197/4425/files/camaro_lt1_manual_transmission.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f8741180325e.pdf
- https://cdn-cms.f-static.net/uploads/4366958/normal_5f87698c2f7ad.pdf
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f874c846ac75.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f87774038cf7.pdf
- https://cdn.shopify.com/s/files/1/0268/7169/3500/files/annoying_gifts_for_a_1_year_old.pdf
- https://cdn.shopify.com/s/files/1/0482/8181/3156/files/the_tao_of_now.pdf
- https://cdn.shopify.com/s/files/1/0433/6615/4394/files/45889369569.pdf
- https://cdn.shopify.com/s/files/1/0438/2516/8544/files/94086229473.pdf
- https://cdn.shopify.com/s/files/1/0487/7248/1190/files/greater_fool_theory_book.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/532013.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/4de2d21244539.pdf
- https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/xazumaziz_wafozuzofati.pdf
Embedded domains
- cctraff.ru
- site-1042548.mozfiles.com
- site-1036637.mozfiles.com
- site-1044148.mozfiles.com
- site-1042509.mozfiles.com
- site-1039173.mozfiles.com
- site-1041086.mozfiles.com
- site-1041291.mozfiles.com
- site-1048535.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- sesuwulot.weebly.com
- fadusoga.weebly.com
- nukevokisoget.weebly.com
- sibakixode.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report