SUSPICIOUS — 2766757.pdf
SUSPICIOUS — 2766757.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ee9c247d1f285683ffa84d141c0305df92e0c59112b31a30329568606256285b - SHA-1:
40ab14b1206f47f58b7e17c682ec17fb3e34222a - MD5:
c39c6bb463ee3c6af07bdad9b9167ff1 - ssdeep:
768:XgGzpDqpmUDrWYwPc/YGATGTw20fTJFwnumE7l1rwd:wGFGpmMkTGn0bJFwnuTJ1rwd - TLSH:
T1C6328DF35493DD4C7A8BAF03ADA72499618AC38C713BA760488C776DC4BCA7D6E10950 - Submitted as: 2766757.pdf
- File type: pdf · Size: 44559 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=craftsman%20dgs%206500, https://cdn.shopify.com/s/files/1/0437/8827/1767/files/29568128947.pdf, https://cdn.shopify.com/s/files/1/0484/3316/8552/files/business_analytics_books.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=craftsman%20dgs%206500
- https://cdn.shopify.com/s/files/1/0437/8827/1767/files/29568128947.pdf
- https://cdn.shopify.com/s/files/1/0484/3316/8552/files/business_analytics_books.pdf
- https://cdn.shopify.com/s/files/1/0433/8896/0933/files/yugioh_capsule_monster_coliseum_elements.pdf
- https://cdn.shopify.com/s/files/1/0498/7243/7406/files/scott_kingsley_swift.pdf
- https://cdn.shopify.com/s/files/1/0498/9639/0814/files/wimpy_kid_double_down_free.pdf
- https://cdn.shopify.com/s/files/1/0496/6360/6933/files/scotland_national_anthem_earrape.pdf
- https://uploads.strikinglycdn.com/files/7ae83622-98ca-429f-a1bf-f95322e58d45/61410371320.pdf
- https://uploads.strikinglycdn.com/files/c0605f24-e628-4482-9037-3a0e03664716/48262131681.pdf
- https://uploads.strikinglycdn.com/files/20a04b9f-bdf3-4d93-af4a-a6a253bed8c7/wolikesipoli.pdf
- https://uploads.strikinglycdn.com/files/6b7b7baa-5988-40a8-9437-b6392ece6776/tofofobupezosexavinusekur.pdf
- https://uploads.strikinglycdn.com/files/73a3ee0d-dd44-45b9-bf18-f7aa3a10612e/65020847986.pdf
- https://uploads.strikinglycdn.com/files/0c966f9e-f14e-4314-818f-8f90b80948ac/pumomopora.pdf
- https://uploads.strikinglycdn.com/files/db739a9c-5323-4a79-81ca-e468425f7aee/nanegelaketa.pdf
- https://uploads.strikinglycdn.com/files/58ae7983-0724-4989-aab4-504beab637a9/fesuvobosusuzipave.pdf
- https://uploads.strikinglycdn.com/files/17626bda-7047-4717-a1dc-e2d1a546f3a0/mepoga.pdf
- https://site-1039332.mozfiles.com/files/1039332/tefibulipijevim.pdf
- https://site-1039654.mozfiles.com/files/1039654/nomepatixu.pdf
- https://uploads.strikinglycdn.com/files/fbd660a9-3e67-443d-ad86-d70e20b0e6ca/54293563212.pdf
- https://uploads.strikinglycdn.com/files/e9cfefde-6258-4659-a545-921d8882122a/vagitesilewajerusipapufe.pdf
- https://uploads.strikinglycdn.com/files/33216c98-381e-4215-b04d-380ca4ceb88d/mofodowilofabosupojideka.pdf
- https://uploads.strikinglycdn.com/files/60d1b9b4-b316-4f59-a775-e66e246e06b0/64811104289.pdf
- https://uploads.strikinglycdn.com/files/4a0d61cb-9068-4651-a1d1-34cb5e5b7d84/38331906706.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039332.mozfiles.com
- site-1039654.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report