SUSPICIOUS — 52887355204.pdf
SUSPICIOUS — 52887355204.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
419dfc2abd559016c6c31c0e3a6288f7d926a7929a8be2eff56e85a18fd2a32f - SHA-1:
f17bffd30295089846eec1c7c2372a2b3fd76127 - MD5:
0c211d16fcc17f663fa40505a6aeeadb - ssdeep:
768:dgGzpDUpGBoDgJROXYAwCNyqc/j/aKBOGzqyGBU/u6/MZIu7bkvU:eGF4pGWBNLc/xMyGy07bkvU - TLSH:
T1AF316DF350A3EE4C7A8BAB576EA71199604AD3892137D7A004C8276CD47CAFD7F00691 - Submitted as: 52887355204.pdf
- File type: pdf · Size: 41336 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=descargar+bbs+tools+tomtom+gratis+softonic, https://uploads.strikinglycdn.com/files/2fb8005c-3c9a-4863-add7-fdfee3c7079c/87628552931.pdf, https://uploads.strikinglycdn.com/files/af931958-5520-4a4e-af9b-a4084c56e7a3/matetufasesidaser.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=descargar+bbs+tools+tomtom+gratis+softonic
- https://uploads.strikinglycdn.com/files/2fb8005c-3c9a-4863-add7-fdfee3c7079c/87628552931.pdf
- https://uploads.strikinglycdn.com/files/af931958-5520-4a4e-af9b-a4084c56e7a3/matetufasesidaser.pdf
- https://uploads.strikinglycdn.com/files/b9fc900f-2713-4e28-b772-587535554c4d/zugosuwimaminoredexotuja.pdf
- https://uploads.strikinglycdn.com/files/cf28f997-ab7b-4e4b-abfe-6dc3c0cbe887/rizonalonasukurumebogiku.pdf
- https://uploads.strikinglycdn.com/files/9dfad468-ef08-4c2e-ba46-22124caa3e98/likada.pdf
- https://cdn.shopify.com/s/files/1/0432/2174/5823/files/redistributing_routing_protocols.pdf
- https://cdn.shopify.com/s/files/1/0435/7298/6014/files/46567233636.pdf
- https://cdn.shopify.com/s/files/1/0500/7484/5375/files/list_of_terminal_commands_ubuntu.pdf
- https://cdn.shopify.com/s/files/1/0430/4578/1658/files/windows_10_error_stop_code_unexpected_store_exception.pdf
- https://uploads.strikinglycdn.com/files/1be333b0-d0b3-4ba0-b886-6091437a3a17/wakukedowew.pdf
- https://uploads.strikinglycdn.com/files/55281f51-d982-487a-abe9-0b4140462848/36097920431.pdf
- https://uploads.strikinglycdn.com/files/9b0eccef-0dbc-4693-b730-3b890aca7c98/vopiwuz.pdf
- https://uploads.strikinglycdn.com/files/2b2f1992-32fa-4bfe-b681-d39133b52296/31594609331.pdf
- https://uploads.strikinglycdn.com/files/66fedebf-1869-4832-91d3-95d3e9ba0891/wufixumoberegajexufib.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/gawovepalaselex.pdf
- https://cdn.shopify.com/s/files/1/0498/4376/5403/files/kreepy_krauly_sprinta_manual.pdf
- https://cdn.shopify.com/s/files/1/0488/4080/2469/files/manigaxilibexera.pdf
- https://s3.amazonaws.com/henghuili-files2/40331685365.pdf
- https://s3.amazonaws.com/memul/elenco_giocatori_fantacalcio_2019.pdf
- https://s3.amazonaws.com/leguvefu/l_argumentation_juridique_stefan_goltzberg.pdf
- https://s3.amazonaws.com/subud/83716796172.pdf
- https://s3.amazonaws.com/zuxadol/22198012246.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report