SUSPICIOUS — 5699673.pdf
SUSPICIOUS — 5699673.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
16c7dd284b473940eb08cf952058f05daa7c0018b7bcc55370cf5e7500ff0602 - SHA-1:
23b3cc23aad52fd91bb6835064448f04dcc2e527 - MD5:
d0557727e1bce43509f4271fe0e03f19 - ssdeep:
768:GgGzpDwpYgsDKE066Eg4dN8y4VfUC0Te6gRjBZOrjOBf:TGFkpFsjd+yIUC0Te9CrjOBf - TLSH:
T13C306CF31097EC8C7A8EAF039EE711595189C38D603696644988772DD0BCAFD6F10A61 - Submitted as: 5699673.pdf
- File type: pdf · Size: 35934 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=beamng%20drive%20variety%20mod, https://uploads.strikinglycdn.com/files/6a19bfd2-d348-4cac-91be-10cbc9dd2002/xopokapekapagex.pdf, https://uploads.strikinglycdn.com/files/d9fd37a2-eb7d-48c6-8857-cb89111d1681/97450562737.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=beamng%20drive%20variety%20mod
- https://uploads.strikinglycdn.com/files/6a19bfd2-d348-4cac-91be-10cbc9dd2002/xopokapekapagex.pdf
- https://uploads.strikinglycdn.com/files/d9fd37a2-eb7d-48c6-8857-cb89111d1681/97450562737.pdf
- https://uploads.strikinglycdn.com/files/a7b6d377-4d21-449f-999c-1d6471cfc7de/saboriderixamafegidomag.pdf
- https://uploads.strikinglycdn.com/files/7b110c95-a36f-4c56-a8f3-6b194e699d88/zerapibewugidilepegi.pdf
- https://uploads.strikinglycdn.com/files/1164eeb0-b7fa-4749-aecb-39e68d914f13/33242674696.pdf
- https://site-1040278.mozfiles.com/files/1040278/zedojudu.pdf
- https://site-1044024.mozfiles.com/files/1044024/gebubekujixejaf.pdf
- https://site-1041498.mozfiles.com/files/1041498/24085354764.pdf
- https://naroxelilokatud.weebly.com/uploads/1/3/1/3/131384214/8901906.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/1392291.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/sodotipa.pdf
- https://cdn.shopify.com/s/files/1/0430/6989/8909/files/wiccapedia_journal_a_book_of_shadows.pdf
- https://cdn.shopify.com/s/files/1/0486/0238/2504/files/micro_mini_skirt.pdf
- https://cdn.shopify.com/s/files/1/0434/4584/6168/files/29113462229.pdf
- https://cdn.shopify.com/s/files/1/0503/0615/4692/files/53467906003.pdf
- https://cdn.shopify.com/s/files/1/0495/4809/9736/files/facebook_software_for_android_mobile.pdf
- https://cdn.shopify.com/s/files/1/0497/3215/7601/files/bazagijukesuvulutetiruxin.pdf
- https://site-1039809.mozfiles.com/files/1039809/wesik.pdf
- https://site-1044019.mozfiles.com/files/1044019/sigekugujasivumudiledug.pdf
- https://site-1040347.mozfiles.com/files/1040347/dawapujozigubujibudoraze.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1040278.mozfiles.com
- site-1044024.mozfiles.com
- site-1041498.mozfiles.com
- naroxelilokatud.weebly.com
- xojerajap.weebly.com
- jaserasozupog.weebly.com
- cdn.shopify.com
- site-1039809.mozfiles.com
- site-1044019.mozfiles.com
- site-1040347.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report