SUSPICIOUS — muninasudamenepuzi.pdf
SUSPICIOUS — muninasudamenepuzi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
64afbac8f214e9cc3d82c73f33d1a4e7f11d995f5607c434cf45d356d27b58e8 - SHA-1:
3157988af37ac465695ffc2fd6c09285d20709b5 - MD5:
ebb6e76b5602e98374c3b98b8d0f3111 - ssdeep:
768:ygGzpDBpVLkUvmY1E/VXcs/ZTMuMP/1fXiji3/Gl8iIGfSDzvbkj1XZEIAH:vGFFpY2LPNfpOFfIvkd2H - TLSH:
T11F327DF31197ED4CBA8B9F03AEAB10AA2489C34CA136C79055C8776DC57C3AD7E50960 - Submitted as: muninasudamenepuzi.pdf
- File type: pdf · Size: 44732 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=farmville%202%20cheats%20free, https://cdn-cms.f-static.net/uploads/4366008/normal_5f871073eaf0e.pdf, https://cdn-cms.f-static.net/uploads/4365613/normal_5f8715d274329.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=farmville%202%20cheats%20free
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f871073eaf0e.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f8715d274329.pdf
- https://cdn-cms.f-static.net/uploads/4369305/normal_5f87b1b400c1a.pdf
- https://cdn-cms.f-static.net/uploads/4369323/normal_5f87ba69e0d93.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f87113980aca.pdf
- https://uploads.strikinglycdn.com/files/93fdeaa5-b379-4212-938a-e1b76b232962/lufunebowimalavob.pdf
- https://uploads.strikinglycdn.com/files/b21f2f0b-fc55-4aca-a3f6-b555198c8e30/vibatuvizuburikimad.pdf
- https://site-1044453.mozfiles.com/files/1044453/nubewisuxa.pdf
- https://site-1038343.mozfiles.com/files/1038343/mirosibifusa.pdf
- https://site-1044009.mozfiles.com/files/1044009/wepitexu.pdf
- https://site-1042185.mozfiles.com/files/1042185/96027234490.pdf
- https://site-1037205.mozfiles.com/files/1037205/45288970667.pdf
- https://site-1043837.mozfiles.com/files/1043837/tejixide.pdf
- https://site-1039328.mozfiles.com/files/1039328/56159883538.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/2842d.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bewoti.pdf
- https://paduxadoduxim.weebly.com/uploads/1/3/0/7/130775016/a8ca30cf73.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/7460934.pdf
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/xiluk.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f873c707b01b.pdf
- https://cdn-cms.f-static.net/uploads/4368225/normal_5f877c0b83c93.pdf
- https://cdn-cms.f-static.net/uploads/4366623/normal_5f87a6976354f.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f878b7188079.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1044453.mozfiles.com
- site-1038343.mozfiles.com
- site-1044009.mozfiles.com
- site-1042185.mozfiles.com
- site-1037205.mozfiles.com
- site-1043837.mozfiles.com
- site-1039328.mozfiles.com
- papunagaku.weebly.com
- vuxozajuje.weebly.com
- paduxadoduxim.weebly.com
- nogafuku.weebly.com
- biwugina.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report