SUSPICIOUS — 754593.pdf
SUSPICIOUS — 754593.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
07d1ea0f17c189432c35ef89b2d211eaf59b5edf6677209b420505f34505adb5 - SHA-1:
89438d33f11e434e1cc706456beedbcfecc11fbe - MD5:
e95198d62219ac6c85778ffc4e4ea6a2 - ssdeep:
768:OgGzpD1p40u/IqD0XlZZSfPrQFdgSO2e0PWjXYMXJSFXDQAYgfUuKCyqZm:rGFRpWbkg/2e0P6N4FXDQB0KCyqZm - TLSH:
T1B033ADF750D7ED4C7A9A9B039DAB129EA189C78D5237A7A405CC363DC4BC1AC6F10821 - Submitted as: 754593.pdf
- File type: pdf · Size: 51389 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=adobe%20photoshop%20cs2%20activation%20code%20generator, https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/5948696.pdf, https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/gamukakigofif.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=adobe%20photoshop%20cs2%20activation%20code%20generator
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/5948696.pdf
- https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/gamukakigofif.pdf
- https://paguzijap.weebly.com/uploads/1/3/1/4/131453408/rimek_simevanebijum.pdf
- https://folanejo.weebly.com/uploads/1/3/0/7/130776558/movonirajoviwo.pdf
- https://uploads.strikinglycdn.com/files/d3a3f116-1e32-44c1-8143-184bfb1b072a/91397008896.pdf
- https://uploads.strikinglycdn.com/files/22847899-4e86-46a4-9597-11857c6ab81e/5829932125.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f8753f90473b.pdf
- https://cdn-cms.f-static.net/uploads/4369146/normal_5f88879031764.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f8a70e0ee09f.pdf
- https://tarirubawapub.weebly.com/uploads/1/3/1/6/131606173/2215190.pdf
- https://melegejisud.weebly.com/uploads/1/3/1/3/131379421/34938d4b6eaa9.pdf
- https://naxufubiromu.weebly.com/uploads/1/3/0/7/130738890/lulozepufirisun_pekodipib_lulajirir.pdf
- https://uploads.strikinglycdn.com/files/2da2c8df-3e97-4986-9eb2-ead7ffbc0e0a/2058021500.pdf
- https://uploads.strikinglycdn.com/files/fd1a764d-6f1e-4044-bd62-74216a0daf12/nigekek.pdf
- https://uploads.strikinglycdn.com/files/2db7f48a-a323-40f7-9b53-1f15dbe628b1/9411409021.pdf
- https://uploads.strikinglycdn.com/files/d1324713-060a-4566-8c93-5f4a5d63e5c3/voravi.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f870721a8057.pdf
- https://cdn-cms.f-static.net/uploads/4371543/normal_5f88dd0b16194.pdf
- https://cdn-cms.f-static.net/uploads/4375891/normal_5f89e0d295b82.pdf
- https://cdn-cms.f-static.net/uploads/4371013/normal_5f8960aa54b4c.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f875d41153ce.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- natizupasa.weebly.com
- liwevapazu.weebly.com
- paguzijap.weebly.com
- folanejo.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- tarirubawapub.weebly.com
- melegejisud.weebly.com
- naxufubiromu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report