SUSPICIOUS — 1039640.pdf
SUSPICIOUS — 1039640.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6269fff53ad0daf521bb64389e152312fec0026b2e7f2d22978fe25d16c5ccfd - SHA-1:
84b1a9437243bd535d15887586ad66b35ae0e914 - MD5:
ad116258fb6f1e5008084deb7c5ea5e0 - ssdeep:
1536:SGFAphdde9zSIEphrGmX9lzSOFtvvG/y:LFApxOKphrBX7ltHv - TLSH:
T12A349DF351E3EC4D398B9B036DEE245C5089E7881172EB6558986B2CC43C7ADBB11C61 - Submitted as: 1039640.pdf
- File type: pdf · Size: 57089 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=grand%20fantasia%20reincarnation%20guide, https://uploads.strikinglycdn.com/files/f200deb9-0407-4d30-aa6c-fa647f6bcb1b/fuluxodud.pdf, https://uploads.strikinglycdn.com/files/cf5527d3-6a27-45ca-a801-d1c28d306e2b/wabonerinakebozu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=grand%20fantasia%20reincarnation%20guide
- https://uploads.strikinglycdn.com/files/f200deb9-0407-4d30-aa6c-fa647f6bcb1b/fuluxodud.pdf
- https://uploads.strikinglycdn.com/files/cf5527d3-6a27-45ca-a801-d1c28d306e2b/wabonerinakebozu.pdf
- https://uploads.strikinglycdn.com/files/fde784de-41fc-4ad0-925e-fe352be2c6f3/15608747418.pdf
- https://uploads.strikinglycdn.com/files/d1576e73-7fc9-4799-a655-48b245e3b87a/totupu.pdf
- https://uploads.strikinglycdn.com/files/67991706-8da4-4c45-b1d6-baf4b1aedac0/zevawetukikawitujiwebiz.pdf
- https://xubuvene.weebly.com/uploads/1/3/1/3/131380433/wasategimi.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/5449688.pdf
- https://cdn.shopify.com/s/files/1/0436/7358/3781/files/nifut.pdf
- https://cdn.shopify.com/s/files/1/0488/0810/0005/files/jasumurejexawifelaxi.pdf
- https://cdn.shopify.com/s/files/1/0436/4442/0246/files/spanish_conjunctions_list.pdf
- https://cdn.shopify.com/s/files/1/0497/6967/6961/files/greensboro_nc_craigslist_jobs.pdf
- https://cdn.shopify.com/s/files/1/0428/2381/1239/files/polezasezedovidag.pdf
- https://uploads.strikinglycdn.com/files/8087ddc0-1292-4e5f-8a67-11e28df3a9f8/11865646314.pdf
- https://uploads.strikinglycdn.com/files/bd61806d-fe72-4d50-95d4-d081453392a5/gunojubutupi.pdf
- https://site-1040170.mozfiles.com/files/1040170/53409022069.pdf
- https://site-1042620.mozfiles.com/files/1042620/wizemuwa.pdf
- https://site-1042942.mozfiles.com/files/1042942/50020884669.pdf
- https://site-1042282.mozfiles.com/files/1042282/lubesemewemudegodusowe.pdf
- https://site-1037840.mozfiles.com/files/1037840/81496240054.pdf
- https://cdn.shopify.com/s/files/1/0434/0314/9477/files/75223276674.pdf
- https://cdn.shopify.com/s/files/1/0429/9204/2137/files/the_legend_of_zelda_phantom_hourglass_manual.pdf
- https://cdn.shopify.com/s/files/1/0429/8512/8099/files/wojedenupap.pdf
- https://cdn.shopify.com/s/files/1/0437/1513/3605/files/android_charger_cable_near_me.pdf
- https://cdn.shopify.com/s/files/1/0266/8852/0382/files/winning_eleven_2020_warkop_android_133mb.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- xubuvene.weebly.com
- walijogopabo.weebly.com
- cdn.shopify.com
- site-1040170.mozfiles.com
- site-1042620.mozfiles.com
- site-1042942.mozfiles.com
- site-1042282.mozfiles.com
- site-1037840.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report