SUSPICIOUS — 4918894.pdf
SUSPICIOUS — 4918894.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5d31a69c22e6c1278dd055924732ed229833ee82583a5a94ce0931ab4b93f48d - SHA-1:
b5ea1e194c7ae7324b415a5df37101a9664c6279 - MD5:
18ef945dd2dbc17e10d5e80e290a0802 - ssdeep:
1536:mGFTp07L3giyl/2s8BKzq1zmcRelP08eGKah99zRpWxatVwL:/FTpG32XGacCcElPqG9zRp0atq - TLSH:
T17939CFF756D7ED4C3A835B03A9DB114A5198C7897177DB00818D362C81FCBBEAE508A2 - Submitted as: 4918894.pdf
- File type: pdf · Size: 85682 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=usmc%20bootcamp%20knowledge%20pdf, https://cdn.shopify.com/s/files/1/0436/5506/9849/files/75342031685.pdf, https://cdn.shopify.com/s/files/1/0500/2910/1245/files/takudi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=usmc%20bootcamp%20knowledge%20pdf
- https://cdn.shopify.com/s/files/1/0436/5506/9849/files/75342031685.pdf
- https://cdn.shopify.com/s/files/1/0500/2910/1245/files/takudi.pdf
- https://cdn.shopify.com/s/files/1/0496/0308/4451/files/florida_standards_ela_1st_grade.pdf
- https://uploads.strikinglycdn.com/files/0b0d662c-631f-447c-8ec0-68e8d699a268/46639800761.pdf
- https://uploads.strikinglycdn.com/files/066ee2d2-3d6d-4135-927c-44464efe5ec5/89192712071.pdf
- https://cdn.shopify.com/s/files/1/0492/9326/3004/files/vepozojobegifanifamofa.pdf
- https://cdn.shopify.com/s/files/1/0429/3971/1644/files/low_income_housing_san_jose_available.pdf
- https://site-1043853.mozfiles.com/files/1043853/asus_zenfone_max_plus_m1_manual_update.pdf
- https://site-1044243.mozfiles.com/files/1044243/sepoma.pdf
- https://site-1039346.mozfiles.com/files/1039346/xezewerak.pdf
- https://site-1041770.mozfiles.com/files/1041770/vubibimugififajuwu.pdf
- https://uploads.strikinglycdn.com/files/0bd6783a-c141-4836-a702-635a27319d2b/zaperu.pdf
- https://uploads.strikinglycdn.com/files/695e74f5-9e82-4a07-ab99-2f7b44f9c53d/gegoxujo.pdf
- https://uploads.strikinglycdn.com/files/80becc0d-df49-494d-89e8-d9ff45a192c7/43719071779.pdf
- https://uploads.strikinglycdn.com/files/e96b9de0-9d6b-4957-9d51-c4067a4d51d3/88001770160.pdf
- https://uploads.strikinglycdn.com/files/b89a4f73-4927-4953-9788-dc6ba8344109/delominozoxeligox.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/kefud_libepoj.pdf
- https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/duposikuziwoniziwi.pdf
- https://kafasomawupi.weebly.com/uploads/1/3/0/7/130775431/xowevekufiserur.pdf
- https://sabidodavo.weebly.com/uploads/1/3/1/4/131408103/2915921.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/ce02014a20d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1043853.mozfiles.com
- site-1044243.mozfiles.com
- site-1039346.mozfiles.com
- site-1041770.mozfiles.com
- viweposedijul.weebly.com
- lasajiboz.weebly.com
- kafasomawupi.weebly.com
- sabidodavo.weebly.com
- bedizegoresupa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report