SUSPICIOUS — 9458901.pdf
SUSPICIOUS — 9458901.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a15a5caa9dc2c8b12d045150e0251b1a67dc01442d2cfe43b67c853090821e86 - SHA-1:
7589b9f85acf7d84407177dfb12f57d918fa4ab4 - MD5:
bf19cfa40024011e49d3983b39f1935e - ssdeep:
768:tgGzpDpeFnyrt2wiJbBCKukzegnkKyOyrH1IePuW+CBQ2bXMjEaOWy2yG:OGFleKknpnk9rH1IePCbm8j2/G - TLSH:
T167305BF350A7DD8C7E87AB036EFB156C9089DB88617296584498772CC4BC2BD3F10A61 - Submitted as: 9458901.pdf
- File type: pdf · Size: 39113 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=taurus%20738%20tcp%20magazine, https://cdn-cms.f-static.net/uploads/4367631/normal_5f8774e475a45.pdf, https://cdn-cms.f-static.net/uploads/4366042/normal_5f87000c2d681.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=taurus%20738%20tcp%20magazine
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f8774e475a45.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f87000c2d681.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f8700d12922a.pdf
- https://site-1042020.mozfiles.com/files/1042020/38105297427.pdf
- https://site-1037028.mozfiles.com/files/1037028/65694389875.pdf
- https://site-1038729.mozfiles.com/files/1038729/47742609225.pdf
- https://site-1038629.mozfiles.com/files/1038629/29483712037.pdf
- https://site-1044417.mozfiles.com/files/1044417/18728845211.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/foburadip.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/1145be3e.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/aa94aa7f99c.pdf
- https://cdn-cms.f-static.net/uploads/4368762/normal_5f87e8d72aa6e.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f8760ff2a0a8.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f87ea51c5375.pdf
- https://cdn-cms.f-static.net/uploads/4367304/normal_5f87a6a75e6ef.pdf
- https://cdn.shopify.com/s/files/1/0499/2873/2840/files/national_rice_cooker_cord.pdf
- https://cdn.shopify.com/s/files/1/0433/0638/5576/files/briggs_and_stratton_450_series_148cc_parts_manual.pdf
- https://cdn.shopify.com/s/files/1/0438/1684/5469/files/physics_unit_2_test_answers.pdf
- https://cdn.shopify.com/s/files/1/0433/3164/9689/files/zeruvus.pdf
- https://uploads.strikinglycdn.com/files/3da00fff-af05-41ac-9b40-c66a82b4ae71/refizejoma.pdf
- https://uploads.strikinglycdn.com/files/8a09423f-72a7-49f7-8f85-1c996dea2082/xewixavomuw.pdf
- https://uploads.strikinglycdn.com/files/40070871-a2fe-4e1e-a64f-6ef498259aba/24146348494.pdf
- https://uploads.strikinglycdn.com/files/25aace6f-44e9-45ad-a7eb-e4bfc346a973/17467394940.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1042020.mozfiles.com
- site-1037028.mozfiles.com
- site-1038729.mozfiles.com
- site-1038629.mozfiles.com
- site-1044417.mozfiles.com
- xojerajap.weebly.com
- gusumadanu.weebly.com
- gimejexoxixaza.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report