SUSPICIOUS — 5102960.pdf
SUSPICIOUS — 5102960.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
77bdd2c16cb9bcfb9f1c4f38c919dd87ed8d08d5479e0a317a2134b38b8f9400 - SHA-1:
712d4a6ec9547df93d63f1eeb93100ffee2842c0 - MD5:
36ecf76523a0e761f455046a300bc316 - ssdeep:
768:rgGzpDxpjvWIQsiOXpLhdPNxsOt8JyQ1xTJisNcZ+JzJGVlAZ3mbSNrgnA1CA:UGFlpj+ILiOXdiTM+dylA3NrgnAYA - TLSH:
T163338CF350A3EE4CBA8B5F439DB7118D6849D38DA172A75049886B2CD1BC6FD6F00A11 - Submitted as: 5102960.pdf
- File type: pdf · Size: 49571 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=geometry%20dash%202, https://site-1043576.mozfiles.com/files/1043576/59791795760.pdf, https://site-1040601.mozfiles.com/files/1040601/dademav.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=geometry%20dash%202
- https://site-1043576.mozfiles.com/files/1043576/59791795760.pdf
- https://site-1040601.mozfiles.com/files/1040601/dademav.pdf
- https://site-1038636.mozfiles.com/files/1038636/ginixefo.pdf
- https://site-1039789.mozfiles.com/files/1039789/bezipazemosi.pdf
- https://site-1038971.mozfiles.com/files/1038971/84148405982.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f87257304157.pdf
- https://cdn-cms.f-static.net/uploads/4367625/normal_5f882ba3d975b.pdf
- https://site-1042539.mozfiles.com/files/1042539/4818700152.pdf
- https://site-1042593.mozfiles.com/files/1042593/xasej.pdf
- https://site-1042768.mozfiles.com/files/1042768/rikudo.pdf
- https://cdn.shopify.com/s/files/1/0501/5899/3558/files/total_heat_capacity_formula.pdf
- https://cdn.shopify.com/s/files/1/0432/3239/5423/files/muji_aroma_diffuser_user_manual.pdf
- https://cdn.shopify.com/s/files/1/0466/3587/6517/files/15973644280.pdf
- https://cdn.shopify.com/s/files/1/0496/7795/9325/files/ritopewavisotapile.pdf
- https://cdn.shopify.com/s/files/1/0266/9304/2355/files/gopar.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/zuzobokodetaxuj.pdf
- https://kusanogiwaxug.weebly.com/uploads/1/3/0/8/130873987/vavupiw_jalonoburute.pdf
- https://pobezewimo.weebly.com/uploads/1/3/2/6/132681951/rumesipajukag.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f8736ba2f434.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8807a7cc584.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f87f69b2b050.pdf
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f87801f43a76.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f8762e55dc3f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- site-1043576.mozfiles.com
- site-1040601.mozfiles.com
- site-1038636.mozfiles.com
- site-1039789.mozfiles.com
- site-1038971.mozfiles.com
- cdn-cms.f-static.net
- site-1042539.mozfiles.com
- site-1042593.mozfiles.com
- site-1042768.mozfiles.com
- cdn.shopify.com
- juragubiv.weebly.com
- kusanogiwaxug.weebly.com
- pobezewimo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report