SUSPICIOUS — zupaja.pdf
SUSPICIOUS — zupaja.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
57fc5f42959733c1523f1d987aea08e233a78ccf37b919e9e0ae88fd4fd01298 - SHA-1:
658b7bf0229fdc774b3c213083efce1b06899549 - MD5:
4d4296f131b426110dde5fe761a78b1f - ssdeep:
768:jgGzpDaeoS0E87S+L08aGxDSfcThx6RroUmulVK8OjbVD4ACl98cuWgQBLYDyPLh:cGFOeE6LRVKdbJFCAc2QhJegMaT - TLSH:
T1BC338DF31097DE8CBB4AAB13ADB710AA558EDA4D6133E7A0448C732CC57C5BD6E14A10 - Submitted as: zupaja.pdf
- File type: pdf · Size: 51920 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20bone%20collector%20book%20review, https://cdn-cms.f-static.net/uploads/4366947/normal_5f87452f3119f.pdf, https://cdn-cms.f-static.net/uploads/4368229/normal_5f87cfd1913bf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20bone%20collector%20book%20review
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f87452f3119f.pdf
- https://cdn-cms.f-static.net/uploads/4368229/normal_5f87cfd1913bf.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f8777bfa63b8.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f876f264735a.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f87a1064aec0.pdf
- https://cdn.shopify.com/s/files/1/0494/2305/7051/files/69_trans_am_value.pdf
- https://cdn.shopify.com/s/files/1/0485/0699/4850/files/38436045740.pdf
- https://cdn.shopify.com/s/files/1/0433/5098/2805/files/83798163854.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f87ba6d8c451.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f874caac9211.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f874d6da2468.pdf
- https://uploads.strikinglycdn.com/files/bbf3d046-29fb-4e76-bb76-eefa7024e7b7/30601220989.pdf
- https://uploads.strikinglycdn.com/files/2513d467-5948-45e2-8675-adb029faa113/nelakizulejefigemekigila.pdf
- https://uploads.strikinglycdn.com/files/d5982f8b-d9bd-4694-8495-a802ac35640f/18321079720.pdf
- https://uploads.strikinglycdn.com/files/6e7557ba-76fb-4039-8b8b-661d80beeaec/75984192568.pdf
- https://uploads.strikinglycdn.com/files/7684afaa-672a-4aec-9e52-9fc4d6d80542/78906772104.pdf
- https://cdn.shopify.com/s/files/1/0440/7744/9366/files/polmedia_polish_pottery.pdf
- https://cdn.shopify.com/s/files/1/0497/5198/2233/files/audacity_recording_app_for_android.pdf
- https://cdn.shopify.com/s/files/1/0488/1488/2981/files/realidades_1_teacher_edition.pdf
- https://cdn.shopify.com/s/files/1/0484/2992/4509/files/cricket_darts_rules_scoring.pdf
- https://cdn.shopify.com/s/files/1/0465/2384/2718/files/93087657756.pdf
- https://site-1038530.mozfiles.com/files/1038530/vufivikosurov.pdf
- https://site-1040683.mozfiles.com/files/1040683/73084710544.pdf
- https://site-1042768.mozfiles.com/files/1042768/2020_dodge_magnum_sxt_manual.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1038530.mozfiles.com
- site-1040683.mozfiles.com
- site-1042768.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report