SUSPICIOUS — 173668.pdf
SUSPICIOUS — 173668.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5908ceb71e14f7f2bdfcc6b9deb9c013d0876a6dceb971c88cbf782b4f490654 - SHA-1:
dd89b426fb0696c7476673fb2fffd5d887148aaf - MD5:
f0db650c402f8f7438379652e25ea31a - ssdeep:
768:FgGzpDApEQio0ogmPnQaYlyPtu/oWtLUpi2Fl/qb3OKeQzWlw0:WGFMpbIipicl/QOKeQWlw0 - TLSH:
T132327CF70097ED4CBAC7AB13ACEA11966099C3C9A226E750248C7B7DD47C67D3E50920 - Submitted as: 173668.pdf
- File type: pdf · Size: 43297 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=metaprogramming%20ruby%202%20pdf, https://cdn-cms.f-static.net/uploads/4367300/normal_5f878ec009a4a.pdf, https://cdn-cms.f-static.net/uploads/4366347/normal_5f880ae271343.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=metaprogramming%20ruby%202%20pdf
- https://cdn-cms.f-static.net/uploads/4367300/normal_5f878ec009a4a.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f880ae271343.pdf
- https://cdn-cms.f-static.net/uploads/4367286/normal_5f879b7aca3c3.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f871a2853db7.pdf
- https://site-1040575.mozfiles.com/files/1040575/40455194681.pdf
- https://site-1039737.mozfiles.com/files/1039737/fomorosusugoluxigija.pdf
- https://site-1048215.mozfiles.com/files/1048215/gulawixafurozedidu.pdf
- https://site-1043475.mozfiles.com/files/1043475/xafojugopetefesebufosegaf.pdf
- https://site-1042511.mozfiles.com/files/1042511/jagutudonapavulinim.pdf
- https://site-1037850.mozfiles.com/files/1037850/motolaleworom.pdf
- https://site-1044440.mozfiles.com/files/1044440/88904164018.pdf
- https://site-1043765.mozfiles.com/files/1043765/40769033903.pdf
- https://cdn.shopify.com/s/files/1/0433/2358/8773/files/modern_combat_5_apk_mod_data.pdf
- https://cdn.shopify.com/s/files/1/0428/5952/8355/files/55331429993.pdf
- https://cdn.shopify.com/s/files/1/0439/1016/8744/files/utilization_of_electrical_energy_and_traction.pdf
- https://cdn.shopify.com/s/files/1/0481/5234/6777/files/unity_reorderable_list_attribute.pdf
- https://cdn.shopify.com/s/files/1/0484/7645/5066/files/tezemetegixe.pdf
- https://buxivadoga.weebly.com/uploads/1/3/0/7/130740323/e8f84e3.pdf
- https://kokexofagisukop.weebly.com/uploads/1/3/2/7/132710589/jakim-tupanadixuru-jovigiwubareje-gixeretokuv.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/8925184.pdf
- https://site-1037212.mozfiles.com/files/1037212/fexawasinevibisedavozewi.pdf
- https://site-1040558.mozfiles.com/files/1040558/51738324402.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1040575.mozfiles.com
- site-1039737.mozfiles.com
- site-1048215.mozfiles.com
- site-1043475.mozfiles.com
- site-1042511.mozfiles.com
- site-1037850.mozfiles.com
- site-1044440.mozfiles.com
- site-1043765.mozfiles.com
- cdn.shopify.com
- buxivadoga.weebly.com
- kokexofagisukop.weebly.com
- vuxozajuje.weebly.com
- site-1037212.mozfiles.com
- site-1040558.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report