SUSPICIOUS — 7ff520b306.pdf
SUSPICIOUS — 7ff520b306.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
f856506c3c01e530990656dab2b97691b02eef8556be857dddf246c62997f25f - SHA-1:
f5295439751f30e049b864515d553f72031b79c9 - MD5:
45ef2735d8cdb33076cd1dd4c2c91bd5 - ssdeep:
768:KgGzpD5pPw65J1+7LO8b/CAokt5vcoerWkAWSiVLnwAy3b0ZGtGG4qVezXpPT:XGFtpGXdt5URrW9WbTyLZV0RT - TLSH:
T1C0329EF35093EC8DB9869B03ADEB21665189C749A033976014CC773DD17CABEBE11960 - Submitted as: 7ff520b306.pdf
- File type: pdf · Size: 44701 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=physiology%20of%20kidney%20pdf, https://cdn.shopify.com/s/files/1/0478/0536/6431/files/85423641288.pdf, https://cdn.shopify.com/s/files/1/0497/4244/6753/files/lulavekinunigovemi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=physiology%20of%20kidney%20pdf
- https://cdn.shopify.com/s/files/1/0478/0536/6431/files/85423641288.pdf
- https://cdn.shopify.com/s/files/1/0497/4244/6753/files/lulavekinunigovemi.pdf
- https://cdn.shopify.com/s/files/1/0499/9371/1776/files/72549042959.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f8733cb83b3e.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f875d9c4e995.pdf
- https://cdn-cms.f-static.net/uploads/4366408/normal_5f8892b3661e5.pdf
- https://uploads.strikinglycdn.com/files/e6203c14-4c83-4e40-80e8-b330a03ae075/18261846072.pdf
- https://uploads.strikinglycdn.com/files/252f9bf3-6543-45b0-8f96-83caa7efdfe7/tafarebadafixik.pdf
- https://uploads.strikinglycdn.com/files/cb8c12e4-5c67-48e1-af9b-3b13bead126a/regebaxuxuluwufaz.pdf
- https://uploads.strikinglycdn.com/files/9aae2a3a-beb6-487b-b396-17c03365db3d/79912418521.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/wirexanusir.pdf
- https://tegugozitofo.weebly.com/uploads/1/3/0/8/130874592/bofax-momepunewi-fovilugi.pdf
- https://femevidawivuk.weebly.com/uploads/1/3/1/0/131071063/2625402.pdf
- https://zulatikuwa.weebly.com/uploads/1/3/0/7/130776211/9673907.pdf
- https://uploads.strikinglycdn.com/files/82b2f5f9-566e-4b55-baf7-9ae09eb8e70b/39129739568.pdf
- https://uploads.strikinglycdn.com/files/eb2b4133-3dcf-49cd-b423-ad04cddb10c2/viramuzufos.pdf
- https://cdn.shopify.com/s/files/1/0496/6812/8925/files/57328864905.pdf
- https://cdn.shopify.com/s/files/1/0266/8671/8126/files/16347225853.pdf
- https://cdn.shopify.com/s/files/1/0501/2242/4480/files/91000889446.pdf
- https://cdn.shopify.com/s/files/1/0501/1302/0054/files/57055984550.pdf
- https://cdn.shopify.com/s/files/1/0430/3860/5461/files/eneide_libro_2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- fijojonibiw.weebly.com
- tegugozitofo.weebly.com
- femevidawivuk.weebly.com
- zulatikuwa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report