SUSPICIOUS — 2593159.pdf
SUSPICIOUS — 2593159.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2b76d8551b04477e8533fe5db84a158d8c30b2bb41f3be8f8cb984aa6dbd159d - SHA-1:
eb94b4c64355fa6a4a944a309ff35526e59be27f - MD5:
fed4f5a0e539259fae19fe3d26ed9099 - ssdeep:
1536:SGFde/+YC71KLj4wh5p4oDXnmX/nMr0cb:LFde/X1P4Q5fDXnmXvMr/ - TLSH:
T130349DF35097CD9C7A86A703B9FB2115608D874C2233A764588C3B6CD4BC3BD6E54A61 - Submitted as: 2593159.pdf
- File type: pdf · Size: 53069 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=percy%20jackson%20lightning%20thief%20chapter%2018%20summary, https://uploads.strikinglycdn.com/files/0f357449-04bf-4401-9c95-7c2a38f3a689/kavoxubuv.pdf, https://uploads.strikinglycdn.com/files/cd68f225-e97d-4da9-9d1c-0b822fabbca0/37863824984.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=percy%20jackson%20lightning%20thief%20chapter%2018%20summary
- https://uploads.strikinglycdn.com/files/0f357449-04bf-4401-9c95-7c2a38f3a689/kavoxubuv.pdf
- https://uploads.strikinglycdn.com/files/cd68f225-e97d-4da9-9d1c-0b822fabbca0/37863824984.pdf
- https://uploads.strikinglycdn.com/files/72fbf8c6-b629-4403-83a3-09b91f07508b/tasokagikoru.pdf
- https://uploads.strikinglycdn.com/files/97476a6b-5b7f-4ec3-8112-4a2e3bdd8cdb/73942759533.pdf
- https://uploads.strikinglycdn.com/files/0a193111-fe20-4865-8c2d-9cdc1b379915/kogabopibevopuzifubijin.pdf
- https://uploads.strikinglycdn.com/files/ba9f574a-a41c-4dd5-b596-4758bb5b0b1b/9891331490.pdf
- https://cdn.shopify.com/s/files/1/0433/7981/8661/files/ark_survival_evolved_griffin_spawn_code.pdf
- https://cdn.shopify.com/s/files/1/0436/9501/4042/files/dikese.pdf
- https://cdn.shopify.com/s/files/1/0484/9929/4369/files/gosuleban.pdf
- https://cdn.shopify.com/s/files/1/0268/7559/2888/files/post_graduate_project_topics_in_biology_education.pdf
- https://site-1036871.mozfiles.com/files/1036871/6851582215.pdf
- https://site-1037827.mozfiles.com/files/1037827/jusuxiboduzuterizuro.pdf
- https://cdn.shopify.com/s/files/1/0498/4494/5051/files/39141519445.pdf
- https://cdn.shopify.com/s/files/1/0482/8417/2449/files/cleveland_plain_dealer_obituaries_archives.pdf
- https://cdn.shopify.com/s/files/1/0497/3366/4922/files/how_to_facilitate_a_support_group_online.pdf
- https://cdn.shopify.com/s/files/1/0497/3235/4205/files/sogaboza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1036871.mozfiles.com
- site-1037827.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report