SUSPICIOUS — 4839439.pdf
SUSPICIOUS — 4839439.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4b7cc3c895e39b598aa900942883a4375add052026e1e18e550b05901bccf7ed - SHA-1:
810924d8b746f7cfbb806370426607ee90fea4b5 - MD5:
a26c7adab9346307b0175983ccda914c - ssdeep:
1536:XGFjptaiG+8ovClf4lCzEEHwQetfyPWy9OjluCqS:2FjptaRGhl2E0tetKv9nu - TLSH:
T19E36BEF300A7ED4CB947AB03BEBB1558A54EC3496132DBA0959973ACC57C2AC6F50E10 - Submitted as: 4839439.pdf
- File type: pdf · Size: 67314 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=terraria%203ds%20guide, https://cdn-cms.f-static.net/uploads/4366362/normal_5f87c55fba4bd.pdf, https://cdn-cms.f-static.net/uploads/4366048/normal_5f86fc5c911cd.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=terraria%203ds%20guide
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f87c55fba4bd.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f86fc5c911cd.pdf
- https://cdn-cms.f-static.net/uploads/4366382/normal_5f872cb28bfd6.pdf
- https://cdn-cms.f-static.net/uploads/4369306/normal_5f884d3fa3d9d.pdf
- https://uploads.strikinglycdn.com/files/8d2c2ce4-e4c9-4085-bbe1-68fa407fe1c4/22699340430.pdf
- https://uploads.strikinglycdn.com/files/6c39751e-e0a3-4b01-8242-4a51ba8d36f1/lukirebeboxedunavega.pdf
- https://uploads.strikinglycdn.com/files/950ad7cf-f3d4-4f1b-b762-1766bd1fd292/vojetuxasudokisomonixube.pdf
- https://site-1040000.mozfiles.com/files/1040000/nifagozuxaren.pdf
- https://site-1039885.mozfiles.com/files/1039885/70194742563.pdf
- https://site-1042191.mozfiles.com/files/1042191/bupesitifaj.pdf
- https://site-1036848.mozfiles.com/files/1036848/dajasodene.pdf
- https://site-1043453.mozfiles.com/files/1043453/popanawajineruremak.pdf
- https://uploads.strikinglycdn.com/files/f848800d-ca9b-43f8-8c36-a3e9e65ec19c/kaxaboxuximugukenorima.pdf
- https://uploads.strikinglycdn.com/files/c36d20f9-9e6e-4546-8782-98b06677cdaa/88029180975.pdf
- https://uploads.strikinglycdn.com/files/a3bc9227-f27e-4bf0-8581-23c150cf0939/mupujusi.pdf
- https://uploads.strikinglycdn.com/files/440a9e8a-422f-491a-920a-6917bc44bcde/bozumovavutofetuzodu.pdf
- https://uploads.strikinglycdn.com/files/2c748661-8eb9-4413-b6e5-e760e66aecbd/96323245450.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/zirilapalir-bisojexowesomes.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/divili_dapixi.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7360136.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1040000.mozfiles.com
- site-1039885.mozfiles.com
- site-1042191.mozfiles.com
- site-1036848.mozfiles.com
- site-1043453.mozfiles.com
- jiwepurojal.weebly.com
- jakedekokobara.weebly.com
- genigudepa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report