SUSPICIOUS — basififavelo.pdf
SUSPICIOUS — basififavelo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
78c3ce7fd5b16018104e2c04e75cf7dbe413b68b27d48193de782d3ef1963531 - SHA-1:
62bca08e69f466a2ef6d4ffda86bca93c21df830 - MD5:
6fafd9060e32af4de537361ad7b57d21 - ssdeep:
768:G3gGzpDryrv76qf7X1dxnj1IT2+flKLHjqfhq71/JBysJshrwY7HwK:/GFqRutKLHjGyxJByEsbHwK - TLSH:
T14C308EF75097ED8C3A8AAB136EAA155D6149C7CC717282A008C8377CC4BC5FDAE40D60 - Submitted as: basififavelo.pdf
- File type: pdf · Size: 39281 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20backyardigans%20chichen%20itza%20pizza, https://uploads.strikinglycdn.com/files/fb8f627d-8d33-4c61-b035-06819009f18b/the_pomodoro_technique.pdf, https://cdn-cms.f-static.net/uploads/4380073/normal_5f8ff4636739f.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20backyardigans%20chichen%20itza%20pizza
- https://uploads.strikinglycdn.com/files/fb8f627d-8d33-4c61-b035-06819009f18b/the_pomodoro_technique.pdf
- https://cdn-cms.f-static.net/uploads/4380073/normal_5f8ff4636739f.pdf
- https://cdn-cms.f-static.net/uploads/4402720/normal_5f94f41e1613a.pdf
- https://uploads.strikinglycdn.com/files/6a8b8dc9-722d-4d45-95af-2d2b27503200/76854209351.pdf
- https://cdn-cms.f-static.net/uploads/4385028/normal_5f8ee89705122.pdf
- https://uploads.strikinglycdn.com/files/c09b544e-dd59-41d2-a1b2-eb4dfa28bb81/89721417683.pdf
- https://cdn-cms.f-static.net/uploads/4366642/normal_5f8911ea0027b.pdf
- https://cdn-cms.f-static.net/uploads/4373749/normal_5f9e05a34f767.pdf
- https://cdn-cms.f-static.net/uploads/4371269/normal_5f9a3057a281b.pdf
- https://cdn-cms.f-static.net/uploads/4417815/normal_5f964933a1f93.pdf
- https://uploads.strikinglycdn.com/files/ef995d9b-95ee-41f4-a0cf-faa80d0dc04e/hyde_park_trail_map.pdf
- https://cdn-cms.f-static.net/uploads/4384460/normal_5f914e91e7163.pdf
- https://uploads.strikinglycdn.com/files/f8b79a1a-3c15-48ea-8488-f294d77a7ae6/zigitiwa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report