SUSPICIOUS — 5037451.pdf
SUSPICIOUS — 5037451.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1b9b14b975ba10313552153975181517079e5678489b06b63c94186e4bb66ec9 - SHA-1:
541fc5d8345860694d5e63bd93e6d8f2721f4558 - MD5:
fe0a55d432ad9c68cec0d3d1402c0d02 - ssdeep:
768:WgGzpDlp8GVt9jMNjI/f41z5umtuuPXYax90EkNzImw4l9O7awM:DGFxpFmt6fEkNEF4l9O7awM - TLSH:
T17D327DF750D3ED8C7A8BEB13ADBB14AA158AC74860769750458C773DC8BC2AC6E50860 - Submitted as: 5037451.pdf
- File type: pdf · Size: 44177 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=conan%20exiles%20smelter%20thrall, https://cdn.shopify.com/s/files/1/0432/0546/0125/files/veromos_summoners_war_info.pdf, https://cdn.shopify.com/s/files/1/0478/6651/1526/files/bepiwogotejofulekelele.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=conan%20exiles%20smelter%20thrall
- https://cdn.shopify.com/s/files/1/0432/0546/0125/files/veromos_summoners_war_info.pdf
- https://cdn.shopify.com/s/files/1/0478/6651/1526/files/bepiwogotejofulekelele.pdf
- https://cdn.shopify.com/s/files/1/0433/3702/3641/files/society_the_basics_13th_edition_ebook.pdf
- https://cdn.shopify.com/s/files/1/0486/0195/6520/files/east_is_east_and_west_is_west_and_the_wrong_one_i_have_chosen.pdf
- https://cdn.shopify.com/s/files/1/0483/9043/9080/files/prem_ratan_dhan_payo_movie_download_filmyzilla.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86fbbc85d79.pdf
- https://cdn-cms.f-static.net/uploads/4366973/normal_5f87829488182.pdf
- https://site-1039869.mozfiles.com/files/1039869/28691514926.pdf
- https://site-1039608.mozfiles.com/files/1039608/86693443814.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f86f8937d2ea.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f87582dd839e.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f876357a291f.pdf
- https://cdn-cms.f-static.net/uploads/4368954/normal_5f879ad64b3ab.pdf
- https://uploads.strikinglycdn.com/files/7d8ec858-8f33-4f65-8c61-3fe46893d965/nufoginagusu.pdf
- https://uploads.strikinglycdn.com/files/5f5deee7-5c72-4b34-aed7-11a0093479ae/83430917026.pdf
- https://uploads.strikinglycdn.com/files/24b105ba-8972-4c34-afb7-41e06a324424/6834211334.pdf
- https://uploads.strikinglycdn.com/files/7db9b6a2-38f7-4ec8-ab67-33d7f0c1306d/zusaxosabeboraxelefepav.pdf
- https://uploads.strikinglycdn.com/files/b5e836af-81bb-49cd-b530-58b96173b399/giruweza.pdf
- https://uploads.strikinglycdn.com/files/917f50d1-42a4-4d8a-8fec-cc3cb98e56ac/gedesalubixu.pdf
- https://uploads.strikinglycdn.com/files/3d08d21a-2114-4a5e-8da5-feab0054d2b3/55088567836.pdf
- https://uploads.strikinglycdn.com/files/51ef3748-ad4c-4861-9041-881da6cd1ae6/nixilijuwowax.pdf
- https://uploads.strikinglycdn.com/files/faf25019-5ba3-4676-9882-4ec9e756649d/47358954488.pdf
- https://uploads.strikinglycdn.com/files/5af732c5-441e-49e4-97a2-cf763cd1e811/jebitenulabaxu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1039869.mozfiles.com
- site-1039608.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report