SUSPICIOUS — 41417696211.pdf
SUSPICIOUS — 41417696211.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5e7f905da1cf1f081ceb56c9fc809534b37a7829e1fda28cc1e533882130ec25 - SHA-1:
60e68fd057be532eafe443888469598ccdb830c5 - MD5:
cacd4c14d5aedf0240b5e032c7e0d683 - ssdeep:
1536:HGFler46KJEbPTYxPikY6sEFK29T3WnB:mFlekrE3KsEw29T34 - TLSH:
T1A234BFF7085BED8CB986AB039DFA109B218AC74D6173EA60099C376CD47C5BD7E00961 - Submitted as: 41417696211.pdf
- File type: pdf · Size: 52695 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=convert+ms+project+plan+to+pdf, https://uploads.strikinglycdn.com/files/3ea4eaaf-88d1-420c-bc9c-b7387946d77e/kogoxufijumefaj.pdf, https://uploads.strikinglycdn.com/files/c381918b-54fb-4353-9ecb-992f543c4274/nosewo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=convert+ms+project+plan+to+pdf
- https://uploads.strikinglycdn.com/files/3ea4eaaf-88d1-420c-bc9c-b7387946d77e/kogoxufijumefaj.pdf
- https://uploads.strikinglycdn.com/files/c381918b-54fb-4353-9ecb-992f543c4274/nosewo.pdf
- https://uploads.strikinglycdn.com/files/bf4e96a2-9386-447c-99fb-7be20882a57b/92712230431.pdf
- https://uploads.strikinglycdn.com/files/8da46f63-373c-491a-8af7-7ee8e8e57640/lovulirapunowotosutajebuv.pdf
- https://cdn.shopify.com/s/files/1/0434/7645/1494/files/34935658657.pdf
- https://cdn.shopify.com/s/files/1/0500/2559/5067/files/cold_squad_tv_cast.pdf
- https://cdn.shopify.com/s/files/1/0430/4017/8333/files/dark_cut_2_hacked_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0464/6656/4254/files/ad_free_hulu_apk.pdf
- https://cdn.shopify.com/s/files/1/0482/2679/5672/files/reruforejudofevilojuxew.pdf
- https://cdn.shopify.com/s/files/1/0435/9903/6579/files/demi_lovato_here_we_go_again_tracklist.pdf
- https://cdn.shopify.com/s/files/1/0482/0061/4040/files/84301112237.pdf
- https://cdn.shopify.com/s/files/1/0486/2069/9813/files/41542173966.pdf
- https://cdn.shopify.com/s/files/1/0495/9902/1220/files/chemistry_worksheet_introduction_to_chemical_bonding_answers.pdf
- https://cdn.shopify.com/s/files/1/0437/6530/1400/files/navy_nsu_cover_device.pdf
- https://site-1036748.mozfiles.com/files/1036748/4486473739.pdf
- https://site-1036733.mozfiles.com/files/1036733/resizudufugekavatimetif.pdf
- https://site-1039802.mozfiles.com/files/1039802/16491817787.pdf
- https://site-1038454.mozfiles.com/files/1038454/37171504704.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1036748.mozfiles.com
- site-1036733.mozfiles.com
- site-1039802.mozfiles.com
- site-1038454.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report