SUSPICIOUS — 3374198.pdf
SUSPICIOUS — 3374198.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
02027fd519a2dcd3b3da508606e2937d08a65ae198ad2184fa134d6141ad77cb - SHA-1:
57e471ec3783772f487b5733527716f8faeea5e1 - MD5:
71e7a600861e18812f0d9d1998eb8cba - ssdeep:
768:5SgGzpDdqOKzzBOD69/z0kgJSHamp4AMEhnhf:JGFZ7AVQSH7pnPhnhf - TLSH:
T145318EF35097ED8C7B8AAB03ADB70569608AC38C6132EB60589C777DC47C6AD7D40A50 - Submitted as: 3374198.pdf
- File type: pdf · Size: 39532 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=bergey, https://uploads.strikinglycdn.com/files/92fa62c5-9a4f-4cf4-b680-7d56b973892c/kewazerunuvulitusugorura.pdf, https://latenenagizogip.weebly.com/uploads/1/3/2/6/132696064/fibewobowu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=bergey
- https://uploads.strikinglycdn.com/files/92fa62c5-9a4f-4cf4-b680-7d56b973892c/kewazerunuvulitusugorura.pdf
- https://latenenagizogip.weebly.com/uploads/1/3/2/6/132696064/fibewobowu.pdf
- https://uploads.strikinglycdn.com/files/fc9fda43-68fa-4533-9fbf-2e39f2cc1845/the_little_seagull_handbook_3rd_edition_free.pdf
- https://gogipemefa.weebly.com/uploads/1/3/4/4/134471158/0e44713d3a900.pdf
- https://cdn.shopify.com/s/files/1/0480/2812/3295/files/mobius_ff_jp_apk.pdf
- https://cdn.shopify.com/s/files/1/0502/9458/7588/files/2078269083.pdf
- https://uploads.strikinglycdn.com/files/a820c23d-8fc4-4213-a27a-3ac4ca95893a/71273996495.pdf
- https://s3.amazonaws.com/kavitokolezub/protein_metabolism_in_liver.pdf
- https://cdn.shopify.com/s/files/1/0484/6898/3969/files/666901639.pdf
- https://cdn.shopify.com/s/files/1/0437/1513/3605/files/53062678557.pdf
- https://gawubodukajine.weebly.com/uploads/1/3/0/9/130969599/wotuf.pdf
- https://uploads.strikinglycdn.com/files/680c19ad-19ba-4128-9650-2e605eb0c9eb/gunajumas.pdf
- https://uploads.strikinglycdn.com/files/ba287d56-7d7a-4886-96e6-94fc3db641f5/2558999121.pdf
- https://uploads.strikinglycdn.com/files/022121bc-e126-4572-aee8-e79c793cad3f/brandon_grotesque_font.pdf
- https://mufebukevep.weebly.com/uploads/1/3/4/0/134096334/zobavokuvujoz_dobuvivez_kodirujudizo.pdf
- https://uploads.strikinglycdn.com/files/aa99abb0-c098-40a0-920e-912ebed5d45f/kiwelaragobijututogumut.pdf
- https://cdn.shopify.com/s/files/1/0496/7841/8072/files/editor_video_android_premium.pdf
- https://s3.amazonaws.com/dadupawo/15142684943.pdf
- https://uploads.strikinglycdn.com/files/9e886fe1-70b0-4ccd-892a-9d88350fdc2f/pemuporamu.pdf
- https://genifefesabido.weebly.com/uploads/1/3/3/9/133999330/gusiwovuwadexajawex.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- latenenagizogip.weebly.com
- gogipemefa.weebly.com
- cdn.shopify.com
- s3.amazonaws.com
- gawubodukajine.weebly.com
- mufebukevep.weebly.com
- genifefesabido.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report