SUSPICIOUS — a1051.pdf
SUSPICIOUS — a1051.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b7cb705edf840621e3414f448feaab995d588a29ffeea542f9cf3fd70dcd67ac - SHA-1:
5b472176343e76fa8f02e5be15ea4eb7250cc898 - MD5:
0c153ab44b4b1e2fae489cfa1f398347 - ssdeep:
768:DgGzpD7pKxP+kjLUV3YjCMBE0WScEy0k6grcwfNs0GbLhVqEZbfWZ9pa8X1E9c:8GFPp0naS21cwO0Gfhb+ZfaG1E9c - TLSH:
T112329EF354E7EC4C7E46EB47ADB7145A1149C3886236E71098887B2DC9BC6BE7E00960 - Submitted as: a1051.pdf
- File type: pdf · Size: 47350 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=t3620%20mt%20pdf, https://uploads.strikinglycdn.com/files/f8b228aa-b6a8-4192-adb8-9cfa5f87b082/gaderalat.pdf, https://uploads.strikinglycdn.com/files/33088b9e-6714-43d1-bada-6dc647cb97e9/sumedowosawefowi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=t3620%20mt%20pdf
- https://uploads.strikinglycdn.com/files/f8b228aa-b6a8-4192-adb8-9cfa5f87b082/gaderalat.pdf
- https://uploads.strikinglycdn.com/files/33088b9e-6714-43d1-bada-6dc647cb97e9/sumedowosawefowi.pdf
- https://uploads.strikinglycdn.com/files/ec428e2e-7e57-4802-9bca-8105b35d995d/xufakexipuwep.pdf
- https://uploads.strikinglycdn.com/files/8be83af6-69a4-4273-b663-b344aafd6aaa/jejiko.pdf
- https://cdn.shopify.com/s/files/1/0429/3689/3599/files/86386535474.pdf
- https://uploads.strikinglycdn.com/files/6b24f86b-8a36-43a4-8989-df5b122e218e/67927045438.pdf
- https://uploads.strikinglycdn.com/files/0bcf18d0-4108-4dce-a0ae-23c1e4ec07d2/50858565618.pdf
- https://s3.amazonaws.com/mexavofezoxi/medical_laboratory_technology_mcqs.pdf
- https://s3.amazonaws.com/guvovigo/attitude_and_behaviour_in_psychology.pdf
- https://s3.amazonaws.com/pazifetanegapu/konenegipogiki.pdf
- https://s3.amazonaws.com/zafaronivaj/mimitomo.pdf
- https://s3.amazonaws.com/jakujakula/gexopib.pdf
- https://cdn.shopify.com/s/files/1/0498/4868/0610/files/83332040192.pdf
- https://cdn.shopify.com/s/files/1/0485/0057/2315/files/altered_level_of_consciousness_definition.pdf
- https://cdn.shopify.com/s/files/1/0498/2626/7291/files/31123998977.pdf
- https://cdn.shopify.com/s/files/1/0478/9177/5654/files/limitation_of_the_study_example.pdf
- https://cdn.shopify.com/s/files/1/0497/2193/3985/files/35929081146.pdf
- https://uploads.strikinglycdn.com/files/0e36617b-afd3-4f05-96e6-1eb2f96340bd/franchise_business_plan_sample.pdf
- https://uploads.strikinglycdn.com/files/b9a17a8a-6a97-4a6e-9186-4d564d22786a/kawamazebabekevigema.pdf
- https://uploads.strikinglycdn.com/files/10f440c2-b53b-46d5-938c-4f22a0db66fa/bituluset.pdf
- https://uploads.strikinglycdn.com/files/43c46b06-2356-4485-8aed-a6afa93b2c8d/sobepogidit.pdf
- https://uploads.strikinglycdn.com/files/e15ef10d-bccb-4712-8054-4881caee0f91/24641899008.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report