SUSPICIOUS — minupimeva.pdf
SUSPICIOUS — minupimeva.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1fe785ef9dfe9c9c9ba9c1268ce5995991500872a9089f0361ae1eb4109c2449 - SHA-1:
187c659a6887d7660149182b07b3fbfb47951754 - MD5:
5a990f1e11ea4e124f8699acca56b6bd - ssdeep:
768:dgGzpDmpYPQrr1wUIdbiClt1OiwDiCwLKEH4SRku41PXOjl9tLNv1FVG0eeIW:eGFKpxumDiCOj4o4hXOjlnLNvQ0eeIW - TLSH:
T1BC329DF704E3ED4C7A8AA703AEFB01595089D6886136D76046CC3B2CD4BC5ED7E409A2 - Submitted as: minupimeva.pdf
- File type: pdf · Size: 46781 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=e46%20m3%20auto%20to%20manual%20conversion, https://uploads.strikinglycdn.com/files/431c2a26-6318-43ac-b66e-12881408a0f3/5187093999.pdf, https://uploads.strikinglycdn.com/files/d3e734a7-2790-41df-bb05-ba5a9b61a4b0/97750087468.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=e46%20m3%20auto%20to%20manual%20conversion
- https://uploads.strikinglycdn.com/files/431c2a26-6318-43ac-b66e-12881408a0f3/5187093999.pdf
- https://uploads.strikinglycdn.com/files/d3e734a7-2790-41df-bb05-ba5a9b61a4b0/97750087468.pdf
- https://uploads.strikinglycdn.com/files/5a43417f-5838-47e8-8dc4-7bd9bf5a384c/59346744247.pdf
- https://uploads.strikinglycdn.com/files/947d7b53-4a50-4880-99f3-b9a2765c0efc/68725868472.pdf
- https://uploads.strikinglycdn.com/files/43d50698-0a1d-4889-af37-0386dabbd89c/54766570894.pdf
- https://cdn.shopify.com/s/files/1/0437/8260/2904/files/97790240738.pdf
- https://cdn.shopify.com/s/files/1/0483/0412/8164/files/tipo_de_computadora_con_pantalla_tactil.pdf
- https://cdn.shopify.com/s/files/1/0499/6703/8613/files/fireeye_endpoint_agent_installation_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/8821/0837/files/pojibolawa.pdf
- https://cdn.shopify.com/s/files/1/0428/9557/3158/files/elnea_kingdom_beginner_guide.pdf
- https://xonuveviriniw.weebly.com/uploads/1/3/0/7/130738603/6535450.pdf
- https://pisanofinupu.weebly.com/uploads/1/3/1/4/131437881/guxomufasozo.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/4576142.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/javixanupudura.pdf
- https://uploads.strikinglycdn.com/files/2a824630-5735-458b-b5cc-1152d27470cb/23372267699.pdf
- https://uploads.strikinglycdn.com/files/83fcef1b-5384-4644-8777-94655aae63d5/sovulepifezusagokefa.pdf
- https://uploads.strikinglycdn.com/files/00a58bb2-83a5-4a3b-ae2f-c5515f4fb0d2/xevajet.pdf
- https://uploads.strikinglycdn.com/files/ecde12c7-81c7-4932-aa94-94c1ece48e4a/69077548220.pdf
- https://uploads.strikinglycdn.com/files/0cc399b3-3d9f-4a10-a29a-ebdbb48da2df/mini_bike_7_days_to_die.pdf
- https://uploads.strikinglycdn.com/files/56a2ad2c-add9-4d67-b671-5dd5ae1043bd/polojiwasakagamoxijipurow.pdf
- https://cdn.shopify.com/s/files/1/0496/6439/3365/files/dodge_charger_grille_insert.pdf
- https://cdn.shopify.com/s/files/1/0483/9682/8832/files/baseball_card_minimum_size.pdf
- https://cdn.shopify.com/s/files/1/0481/8111/7077/files/81384758672.pdf
- https://cdn.shopify.com/s/files/1/0493/4647/8239/files/54920814969.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- xonuveviriniw.weebly.com
- pisanofinupu.weebly.com
- lagukekejase.weebly.com
- tipefejiri.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report