SUSPICIOUS — 5187418.pdf
SUSPICIOUS — 5187418.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5d7fc1cd4a78e8ea0adf8de99a45e4f5499e9b4c29b92235d3537667489025c5 - SHA-1:
c93f01ff0f0f4fbcf5c302972286894da64b3814 - MD5:
c49f694a4619f74d912d26d298728c32 - ssdeep:
768:PgGzpDaeFSBFt1KtbSg3hsO8qXRnepTcAutu/7+DPyWprp:4GF+eQg3hsTqRehc3w/7+DDprp - TLSH:
T124328DF35097ED4CBACE6F439DA7248DA099C6C86122A6A045C8376CC47C6FD6F10E61 - Submitted as: 5187418.pdf
- File type: pdf · Size: 44645 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=big.%20az%20mp3, https://site-1043200.mozfiles.com/files/1043200/50105977319.pdf, https://site-1043160.mozfiles.com/files/1043160/98524277417.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=big.%20az%20mp3
- https://site-1043200.mozfiles.com/files/1043200/50105977319.pdf
- https://site-1043160.mozfiles.com/files/1043160/98524277417.pdf
- https://site-1040898.mozfiles.com/files/1040898/48985231372.pdf
- https://site-1037028.mozfiles.com/files/1037028/rawawexelalet.pdf
- https://site-1044152.mozfiles.com/files/1044152/59340945184.pdf
- https://uploads.strikinglycdn.com/files/268d3856-1783-40c3-80d4-05591d6f4b05/87852253388.pdf
- https://uploads.strikinglycdn.com/files/527a38c6-e931-4ce9-8ec1-4f4333cc1ada/revizopabototukoruf.pdf
- https://uploads.strikinglycdn.com/files/b082f189-c88d-4de5-aa84-31e543457c79/73708678264.pdf
- https://uploads.strikinglycdn.com/files/c20a4f73-83cc-48df-ade3-e4168865519f/50899035186.pdf
- https://site-1043080.mozfiles.com/files/1043080/71809882260.pdf
- https://site-1041173.mozfiles.com/files/1041173/66741102446.pdf
- https://site-1038504.mozfiles.com/files/1038504/kowetikotegitemad.pdf
- https://site-1042842.mozfiles.com/files/1042842/76164876773.pdf
- https://uploads.strikinglycdn.com/files/81ac2894-aafe-40c9-b429-6fe55f122b2c/49946897841.pdf
- https://uploads.strikinglycdn.com/files/bddf1f53-f237-47a9-a43c-c5691ad71feb/solivinewisiguxufofi.pdf
- https://uploads.strikinglycdn.com/files/0f925db6-2b20-489d-a981-b871429a92ff/zujura.pdf
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f870f01e3119.pdf
- https://cdn-cms.f-static.net/uploads/4365545/normal_5f872cbcb3680.pdf
- https://cdn-cms.f-static.net/uploads/4366645/normal_5f871f6e8a15a.pdf
- http://music.big.az
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- site-1043200.mozfiles.com
- site-1043160.mozfiles.com
- site-1040898.mozfiles.com
- site-1037028.mozfiles.com
- site-1044152.mozfiles.com
- uploads.strikinglycdn.com
- site-1043080.mozfiles.com
- site-1041173.mozfiles.com
- site-1038504.mozfiles.com
- site-1042842.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
- music.big.az
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report