SUSPICIOUS — 9d332512d.pdf
SUSPICIOUS — 9d332512d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
fb91c7096b2ff46bd76d49b7c864b850db3bd2167b97756dc3b96775b5ad3185 - SHA-1:
6f60bf3513b7514a3f37c344c50664e18387f62c - MD5:
f5704839201b338df74c3a96f7c38c8b - ssdeep:
768:SVgGzpDdUey74bGlFsFfiw5R4BBbkYuxTbOfJEfTnBbc3luqVSVGrp85:ZGF6eZr5R4B2T8cTK+VGrp85 - TLSH:
T11F337DF321E7ED4C7A8FAB03AEA71558618ED74DA1269B60548C272CC4BC5FE6F00611 - Submitted as: 9d332512d.pdf
- File type: pdf · Size: 49877 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=wrestling%20school%20in%20florida, https://cdn-cms.f-static.net/uploads/4366351/normal_5f875eb839d18.pdf, https://cdn-cms.f-static.net/uploads/4368471/normal_5f8771f488ef5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=wrestling%20school%20in%20florida
- https://cdn-cms.f-static.net/uploads/4366351/normal_5f875eb839d18.pdf
- https://cdn-cms.f-static.net/uploads/4368471/normal_5f8771f488ef5.pdf
- https://cdn-cms.f-static.net/uploads/4365545/normal_5f8769630846d.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f876f3eb1631.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f87828e9ef2d.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f8773d788565.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f877c62862c8.pdf
- https://uploads.strikinglycdn.com/files/e689b6eb-817f-41d9-b179-d9aa7039a48c/48712881190.pdf
- https://uploads.strikinglycdn.com/files/b40062cc-2a57-467d-861f-c69f2a527b96/63593845684.pdf
- https://uploads.strikinglycdn.com/files/31c59415-d1b7-4869-9969-c47d73b6a97d/82744872408.pdf
- https://uploads.strikinglycdn.com/files/4607c0fb-f327-49fc-9ffc-d7b555f5a3c0/polovosipimutuxip.pdf
- https://uploads.strikinglycdn.com/files/4fe2fe76-7e11-4d89-9216-ec0adfdd3a72/fanurokanizaxasekutimomen.pdf
- https://uploads.strikinglycdn.com/files/c152d325-97d4-485c-93ad-5e5fb33ff114/musonuk.pdf
- https://uploads.strikinglycdn.com/files/65d2b466-e84e-4f80-ae38-717a4107fc94/voxorigituvunilipobanito.pdf
- https://uploads.strikinglycdn.com/files/adda1a65-3365-4692-a9f2-63a0995951a5/39318897014.pdf
- https://uploads.strikinglycdn.com/files/17417193-9450-4dab-b9d8-e1fef1f25104/72712715343.pdf
- https://uploads.strikinglycdn.com/files/d3fe7ef3-eb34-4313-ab41-cd4e8a93766d/tebifuvalavize.pdf
- https://site-1038472.mozfiles.com/files/1038472/85120291479.pdf
- https://site-1037106.mozfiles.com/files/1037106/rijogagiworagogewo.pdf
- https://site-1043646.mozfiles.com/files/1043646/gudugexowalaw.pdf
- https://uploads.strikinglycdn.com/files/c1733db5-e09c-4cab-8e29-07e57d67348a/mexukeroton.pdf
- https://uploads.strikinglycdn.com/files/a77c3617-2481-4ca8-b195-280aac680fa5/tesenojibomixotoz.pdf
- https://uploads.strikinglycdn.com/files/274d26ab-3046-4ffa-836a-70dadc1d757e/kepobagujudas.pdf
- https://uploads.strikinglycdn.com/files/d43fbbe7-47ac-4c57-bb6d-01b4eee8048d/popodowilezudunolokasuloz.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038472.mozfiles.com
- site-1037106.mozfiles.com
- site-1043646.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report