SUSPICIOUS — 481408.pdf
SUSPICIOUS — 481408.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1255c917ca18090e30be7b5f16b2645a652237602da1a4dacdff3e671ce5a175 - SHA-1:
20d7bfcd458c4299eb9e4dc40b02acb2a28f323e - MD5:
cb6493749f84f211f2cfa1d184d3f737 - ssdeep:
768:qgGzpDcup05B1Wf4MP2yrCy4tlpJOKa4QEgZc:3GFgupsB/MP2yrJMFz0EgZc - TLSH:
T11D307DF750A7EC4CBECAAB039EFA11995489D3882136A7A005DC763DC47C6ED7E11860 - Submitted as: 481408.pdf
- File type: pdf · Size: 37539 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pokemon%20rejuvenation%20v12%20download, https://site-1037111.mozfiles.com/files/1037111/rikojakak.pdf, https://site-1037261.mozfiles.com/files/1037261/59687654478.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pokemon%20rejuvenation%20v12%20download
- https://site-1037111.mozfiles.com/files/1037111/rikojakak.pdf
- https://site-1037261.mozfiles.com/files/1037261/59687654478.pdf
- https://site-1038770.mozfiles.com/files/1038770/petakimagerij.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/kuwekewugi.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3079835.pdf
- https://site-1043170.mozfiles.com/files/1043170/66873846670.pdf
- https://site-1036852.mozfiles.com/files/1036852/87067849750.pdf
- https://site-1040775.mozfiles.com/files/1040775/musubiwile.pdf
- https://uploads.strikinglycdn.com/files/8bccb4eb-54e9-4496-a640-2446e442ea11/nerigunulugemolafikegatok.pdf
- https://uploads.strikinglycdn.com/files/237dac73-959b-46c1-b097-c37e2770b36c/47699747686.pdf
- https://uploads.strikinglycdn.com/files/79828f53-06cd-400e-9a98-9cd1ab7b5f0c/55096581211.pdf
- https://uploads.strikinglycdn.com/files/fb16003e-a967-4a41-a7d7-13c51bbdbeaa/66846195705.pdf
- https://uploads.strikinglycdn.com/files/9cdb6dbc-545f-4e0b-b7b6-6534936655cb/2568983006.pdf
- https://uploads.strikinglycdn.com/files/f3abfa54-f98d-4566-972d-ea8bdbc4ce56/98392027177.pdf
- https://uploads.strikinglycdn.com/files/226b5b6e-08b8-4308-b3e5-85d8fdc7101e/lonunudamug.pdf
- https://uploads.strikinglycdn.com/files/76b746c1-4780-4260-8f28-fcaa2919811d/28877682976.pdf
- https://uploads.strikinglycdn.com/files/fc3bc6f9-648e-492b-a4ad-20e885d01a2a/9969759548.pdf
- https://uploads.strikinglycdn.com/files/fc814e0c-1bf4-4097-a314-da3a49cf8f7f/tujevokat.pdf
- https://uploads.strikinglycdn.com/files/58a52c3f-0804-44f8-a71c-f444468e41dd/saratiladuxojize.pdf
- https://uploads.strikinglycdn.com/files/2079cd47-8bf5-448f-90a8-01b8af1a62a4/kupiwijeritomodogomotize.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- site-1037111.mozfiles.com
- site-1037261.mozfiles.com
- site-1038770.mozfiles.com
- zafozudakajadev.weebly.com
- zoxuzuxebexot.weebly.com
- site-1043170.mozfiles.com
- site-1036852.mozfiles.com
- site-1040775.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report