SUSPICIOUS — 421abb.pdf
SUSPICIOUS — 421abb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
26bee88bb366079f0f2e3a9efe37857072edc6b6cda956091bbd9dc8b5b48ac1 - SHA-1:
13c957753bdfb3374998afc9db6dca18998be60f - MD5:
b195d3a74b80e4638d141298bdf18004 - ssdeep:
1536:dGF1pruv5+8Dyz2YQx11Awj3LoyG5/GqynVtKCzPmykXxJ/21hxA4VTYWvbj3+s:gF1p6+8DYhU1nj3MONVQmPlkXxYnA4Vx - TLSH:
T1123AD0F3105BEC897A869F07AD9A1568B54BD6CC603A966094C83B2CC17CBFC3E51B40 - Submitted as: 421abb.pdf
- File type: pdf · Size: 97860 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pterodoras%20granulosus%20fishbase, https://uploads.strikinglycdn.com/files/fb664f53-46b0-4098-be46-a2da494dcb76/60269473669.pdf, https://uploads.strikinglycdn.com/files/8341da87-2408-4362-b2b6-288c62a58a8a/87503486404.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pterodoras%20granulosus%20fishbase
- https://uploads.strikinglycdn.com/files/fb664f53-46b0-4098-be46-a2da494dcb76/60269473669.pdf
- https://uploads.strikinglycdn.com/files/8341da87-2408-4362-b2b6-288c62a58a8a/87503486404.pdf
- https://uploads.strikinglycdn.com/files/51fe3f26-346e-4794-94fb-1c6e2aa97060/80913973008.pdf
- https://uploads.strikinglycdn.com/files/2fcc7073-1386-46d2-b208-816e44fb7f5b/11297746272.pdf
- https://cdn-cms.f-static.net/uploads/4366364/normal_5f88a26976f40.pdf
- https://cdn-cms.f-static.net/uploads/4369657/normal_5f88baba2c19d.pdf
- https://cdn-cms.f-static.net/uploads/4373770/normal_5f88f23691655.pdf
- https://uploads.strikinglycdn.com/files/c6fd3fcf-eb62-433d-a9e0-f2acf0a06030/jexifalu.pdf
- https://uploads.strikinglycdn.com/files/8db0ef2d-e6e5-4db4-8234-bde5a5e2db11/mamiguwek.pdf
- https://uploads.strikinglycdn.com/files/686dd8e8-e080-4474-8cbe-cb749bf1aed2/20024896550.pdf
- https://uploads.strikinglycdn.com/files/5ea13935-4177-4ede-945e-26b5dccb4599/povivepipozuluzajo.pdf
- https://cdn.shopify.com/s/files/1/0478/9528/1830/files/collective_processing_in_sap_sd.pdf
- https://cdn.shopify.com/s/files/1/0481/7924/9301/files/xibesukumuxorika.pdf
- https://cdn.shopify.com/s/files/1/0430/2009/1555/files/cuanto_equivale_10_milimetros_en_pulgadas.pdf
- https://rizebilawi.weebly.com/uploads/1/3/0/8/130814716/muwunenitodilipuz.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8554420.pdf
- https://fulipevaxavu.weebly.com/uploads/1/3/2/6/132695351/725891.pdf
- https://cdn-cms.f-static.net/uploads/4369324/normal_5f889904f11d5.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f8709f6cd9a2.pdf
- https://cdn-cms.f-static.net/uploads/4366304/normal_5f88092530833.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- rizebilawi.weebly.com
- vuxozajuje.weebly.com
- fulipevaxavu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report