SUSPICIOUS — normal_5f871147ae901.pdf
SUSPICIOUS — normal_5f871147ae901.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
091cba9bb086b83f64b5f34ce6bdb76a698ff54205701324cc3be407b292475f - SHA-1:
caabbef950bd0defd78d2c1338b4aefca0d1b3a5 - MD5:
b1dba35f70714534262e72f7a2f3579a - ssdeep:
1536:eGFFpAjm9NaitByzXAEwDruFeJEhFe4TzfU8j1Xl27GUL6QWg7Li1Rp9rJug:HFFpAai/zQZ1ShFdTzfJj1EPL6eyp9 - TLSH:
T13B389FF311A7DC4C7686EB4778B61468714ACF983262A6D044D87B7C84BC6BC6E20B51 - Submitted as: normal_5f871147ae901.pdf
- File type: pdf · Size: 80692 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=lmsw+study+guide+pdf+2020, https://uploads.strikinglycdn.com/files/26c1a15e-63eb-4991-a632-735d8f331b65/79675990232.pdf, https://uploads.strikinglycdn.com/files/e480b6c8-cbc3-471f-8a42-4ead4382c1c8/lurazedelid.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=lmsw+study+guide+pdf+2020
- https://uploads.strikinglycdn.com/files/26c1a15e-63eb-4991-a632-735d8f331b65/79675990232.pdf
- https://uploads.strikinglycdn.com/files/e480b6c8-cbc3-471f-8a42-4ead4382c1c8/lurazedelid.pdf
- https://uploads.strikinglycdn.com/files/99be3931-0997-4953-afef-b5d97c115062/musutomoxa.pdf
- https://uploads.strikinglycdn.com/files/0e002361-c001-4307-9b9e-8d29a6a84275/pusebovazosawomivimedito.pdf
- https://uploads.strikinglycdn.com/files/129268a5-5ad0-4ec5-aaa9-1fada764dfa9/mexatujujarukobivexosubof.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f86f5a28f8af.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f870ec1ba015.pdf
- https://site-1040767.mozfiles.com/files/1040767/33196922372.pdf
- https://site-1042879.mozfiles.com/files/1042879/ridedetal.pdf
- https://uploads.strikinglycdn.com/files/6569c311-f1b4-4ec0-a739-02407314f703/9481370918.pdf
- https://uploads.strikinglycdn.com/files/f6a9bec8-4421-4d48-9341-324c2112047a/liveraxumi.pdf
- https://uploads.strikinglycdn.com/files/5b453e4a-7007-46a8-9790-79ebc54e9a6c/rodogitixerenutufetawiri.pdf
- https://uploads.strikinglycdn.com/files/b0aaffde-f38d-4659-aa4c-ac23d2e33a3c/rinikavipobojevezavitavav.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/5473886.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/18ad995.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf
- https://cdn.shopify.com/s/files/1/0484/3644/5342/files/38622378579.pdf
- https://cdn.shopify.com/s/files/1/0430/1937/0659/files/24_italian_songs_and_arias_high_voice.pdf
- https://cdn.shopify.com/s/files/1/0435/1049/7434/files/narojemuvopozagoxazizupev.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1040767.mozfiles.com
- site-1042879.mozfiles.com
- jatorogerujew.weebly.com
- bedizegoresupa.weebly.com
- dutitujazekap.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report