SUSPICIOUS — 29515c17a0.pdf
SUSPICIOUS — 29515c17a0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3b8994b17035e5d6a64ee3b57a1e7135abc55d11ece369ad6c1aef24fab48298 - SHA-1:
b16649f24c39c14ca4d0f503037fcd1b216bbee5 - MD5:
07e35a0e9fb04c19865ee9ec64c96ff3 - ssdeep:
768:xgGzpDQpGvQ+xLAvhoXefeqyjX/laQYIe39nbO82cajX2sCqPqV3:CGFUpGbEKXefts/IQYIui82caZCqPqV3 - TLSH:
T13D328EF340A3ED4C6AC7DB877ABA5498714786C83522876008DC7BACC5786BD7F508A1 - Submitted as: 29515c17a0.pdf
- File type: pdf · Size: 46032 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=mangal%20deep%20jele%20mp3%20song%20download, https://uploads.strikinglycdn.com/files/572e270d-835b-486f-b58b-e9503dd21cd4/61736940003.pdf, https://uploads.strikinglycdn.com/files/fc677168-45de-4a7f-8ae6-b853861cbce8/lifakuzidixezuzoxuwopum.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=mangal%20deep%20jele%20mp3%20song%20download
- https://s3.amazonaws.com/susopuzupure/wezigizarujodu.pdf
- https://s3.amazonaws.com/zirojopemup/93668146285.pdf
- https://s3.amazonaws.com/wilugugo/29221357426.pdf
- https://s3.amazonaws.com/wonoti/ranafamaxoxosesowixi.pdf
- https://uploads.strikinglycdn.com/files/572e270d-835b-486f-b58b-e9503dd21cd4/61736940003.pdf
- https://s3.amazonaws.com/xanebavifamopez/maburugexisotadutuluzina.pdf
- https://s3.amazonaws.com/jamokaroxoj/handbook_of_poststack_seismic_attributes.pdf
- https://s3.amazonaws.com/zetare/28535371401.pdf
- https://s3.amazonaws.com/tadovu/74209056670.pdf
- https://s3.amazonaws.com/jamokaroxoj/65139931817.pdf
- https://uploads.strikinglycdn.com/files/fc677168-45de-4a7f-8ae6-b853861cbce8/lifakuzidixezuzoxuwopum.pdf
- https://uploads.strikinglycdn.com/files/85b1e035-d14e-4a2d-b672-3d70694aafa4/filibemugavaxelogovek.pdf
- https://uploads.strikinglycdn.com/files/6045391c-28b6-43c0-be48-c9e28e5b7326/bobekudogexopimebub.pdf
- https://uploads.strikinglycdn.com/files/34c9df0d-08a7-4542-b374-a7ffade533ea/fizurozadalozuxevegegodov.pdf
- https://uploads.strikinglycdn.com/files/b356ba76-5549-466e-a887-e63ce24b18c9/fonomopep.pdf
- https://s3.amazonaws.com/pazifetanegapu/6681470701.pdf
- https://s3.amazonaws.com/xanebavifamopez/order_anoplura.pdf
- https://s3.amazonaws.com/henghuili-files2/brute_force_password_online.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report