SUSPICIOUS — sumavi.pdf
SUSPICIOUS — sumavi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
15353d51908b383d0aa53a35def77939a79769e9f261fbb48c9fe1f376981987 - SHA-1:
8834a094a38306ad874a4feeac48d0c98835fca7 - MD5:
4747c21ed8dd7566ec67bca8fee5f943 - ssdeep:
768:8SgGzpD5pjVP3uDBUFVbwHZtY3LISHKwt4Cp8xds6j8OInE5ITInYh:8PGFVpzLk527ISHKwJajj8OInE5ITIn+ - TLSH:
T12A317CF31493ED8C7A86AB03ADFB25552089C6896136A350989C773DD4BC7BD7E20860 - Submitted as: sumavi.pdf
- File type: pdf · Size: 39413 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=janson%20history%20of%20art%20free%20download, https://uploads.strikinglycdn.com/files/4c2ea692-4cf0-467e-9b57-1ac44fbc3672/44857917723.pdf, https://uploads.strikinglycdn.com/files/e42272d3-77a0-4cde-b53c-03456d571916/zakoburaguvadi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=janson%20history%20of%20art%20free%20download
- https://uploads.strikinglycdn.com/files/4c2ea692-4cf0-467e-9b57-1ac44fbc3672/44857917723.pdf
- https://uploads.strikinglycdn.com/files/e42272d3-77a0-4cde-b53c-03456d571916/zakoburaguvadi.pdf
- https://uploads.strikinglycdn.com/files/9ef890af-99e6-4f1c-9219-e0ef8570c343/81116272385.pdf
- https://uploads.strikinglycdn.com/files/d4ae4cc3-c370-4313-81c4-3728039fdbd0/wewazerapadakifigel.pdf
- https://site-1039492.mozfiles.com/files/1039492/wononitojiren.pdf
- https://uploads.strikinglycdn.com/files/f9447d1a-cbe2-4803-896c-e5b54eecbcb9/kajinewu.pdf
- https://uploads.strikinglycdn.com/files/ed75cde7-1a38-4bca-a480-9eb1ef6758d2/48732168478.pdf
- https://uploads.strikinglycdn.com/files/e958cf5b-a532-4970-8a4d-9401a8f63ebf/raputifegebeboxobumirif.pdf
- https://uploads.strikinglycdn.com/files/378a0722-2033-472a-b008-4ea0ba0a4a61/24654564518.pdf
- https://uploads.strikinglycdn.com/files/b044acac-f7bf-4d8f-aedc-ef1846b6525f/63289404220.pdf
- https://cdn.shopify.com/s/files/1/0488/2730/2053/files/harry_london_chocolate.pdf
- https://cdn.shopify.com/s/files/1/0433/1431/5422/files/65704005875.pdf
- https://cdn.shopify.com/s/files/1/0428/3406/7615/files/67818402408.pdf
- https://cdn.shopify.com/s/files/1/0487/0330/7926/files/giriwokanudapiwumujit.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/pokobu-pidoror-pekirez.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/jagufarepa.pdf
- https://site-1040785.mozfiles.com/files/1040785/tafigedudegoledoza.pdf
- https://site-1038649.mozfiles.com/files/1038649/88669799221.pdf
- https://site-1040512.mozfiles.com/files/1040512/fozipotixegozomodum.pdf
- https://site-1041682.mozfiles.com/files/1041682/nipikuz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1039492.mozfiles.com
- cdn.shopify.com
- zoxuzuxebexot.weebly.com
- jukafubu.weebly.com
- site-1040785.mozfiles.com
- site-1038649.mozfiles.com
- site-1040512.mozfiles.com
- site-1041682.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report