SUSPICIOUS — c3f2f6532b01.pdf
SUSPICIOUS — c3f2f6532b01.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
35b6d0ebbb19199ab1e91b4c504191b7207f16f85ff188db30822ac60de505f0 - SHA-1:
accdd63fe96efa30142cfeed5bb19e961e4c6ff5 - MD5:
1c073a52dc231b00ae01f09ef0a3002c - ssdeep:
768:ngGzpDWe8WO5OR4PSETzWp0H6XhabBuIu5/cyNyNvTbO7qTwIFO5Fr:gGFKeM69XoBu75/DNwvTuQEr - TLSH:
T13B315AF310A7ED8C3ACADB03ADAF2559648ADB4C6132A6645488772CC4BC27E7E50950 - Submitted as: c3f2f6532b01.pdf
- File type: pdf · Size: 40129 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=say%20anything%20putlocker, https://uploads.strikinglycdn.com/files/bd718083-67b5-4228-9dd4-074b27b85982/40234496856.pdf, https://uploads.strikinglycdn.com/files/be0a2bbf-9685-4f8a-81cb-f11f8e0fe6fc/51862486445.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=say%20anything%20putlocker
- https://uploads.strikinglycdn.com/files/bd718083-67b5-4228-9dd4-074b27b85982/40234496856.pdf
- https://uploads.strikinglycdn.com/files/be0a2bbf-9685-4f8a-81cb-f11f8e0fe6fc/51862486445.pdf
- https://uploads.strikinglycdn.com/files/1f0e1200-bd84-41dc-95aa-243e2f2b69cb/rupijuganojupimavilikujix.pdf
- https://uploads.strikinglycdn.com/files/790f5d3d-048b-4cf5-9e58-a0893d562efc/57792046842.pdf
- https://cdn.shopify.com/s/files/1/0480/9752/5912/files/36776441315.pdf
- https://site-1039671.mozfiles.com/files/1039671/fogajuvu.pdf
- https://site-1037886.mozfiles.com/files/1037886/kamepebunekikulos.pdf
- https://site-1037188.mozfiles.com/files/1037188/14491941999.pdf
- https://site-1043970.mozfiles.com/files/1043970/69843210884.pdf
- https://site-1040984.mozfiles.com/files/1040984/92964489799.pdf
- https://cdn-cms.f-static.net/uploads/4367667/normal_5f8746658a5b9.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f87774b4671f.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f874ad8e6f61.pdf
- https://uploads.strikinglycdn.com/files/b4541714-afe6-4547-96a5-76857e87b1be/32751668427.pdf
- https://uploads.strikinglycdn.com/files/572c1736-4ad4-4f3a-97b2-9861237e1e16/gimabolaxini.pdf
- https://uploads.strikinglycdn.com/files/75f36548-5aca-461f-ad88-e1287ed9b8ff/56417749518.pdf
- https://uploads.strikinglycdn.com/files/bd61806d-fe72-4d50-95d4-d081453392a5/gunojubutupi.pdf
- https://uploads.strikinglycdn.com/files/dd91126e-e61c-4157-9ee2-8789193a98f1/zovagoxuzo.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/jazulifevalosu.pdf
- https://vevejeda.weebly.com/uploads/1/3/0/7/130776099/wujumoj-womivuzile-subejivanoge-werowubara.pdf
- https://wefolukozik.weebly.com/uploads/1/3/1/4/131406413/1409537.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/nogijazipa-gokokawur.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/a7b88.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1039671.mozfiles.com
- site-1037886.mozfiles.com
- site-1037188.mozfiles.com
- site-1043970.mozfiles.com
- site-1040984.mozfiles.com
- cdn-cms.f-static.net
- jufaxexave.weebly.com
- vevejeda.weebly.com
- wefolukozik.weebly.com
- fanavepuru.weebly.com
- gevafitasib.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report