SUSPICIOUS — dusazavid.pdf
SUSPICIOUS — dusazavid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7f0a7ad2758aeb74b35330cb9144b4a3d3c0085e071e991e6beb08a776c491f3 - SHA-1:
3a5a17da6e4de3da411fb1d25316127ef2474eb0 - MD5:
540e05da3bbebca664b943b658b888e6 - ssdeep:
768:/gGzpDoprNPu1Uo1S8HOy87EWxPir7kzrB8P6cXIdUgU1hcUiIgol+RGNsQft:IGFUpr087EWMHkB8icXIdPU1CU/JlNZt - TLSH:
T170329EF340A7ED4C6BCB9B176DFA1569108AE38CA2379B60059D336DC07C1AD7E20561 - Submitted as: dusazavid.pdf
- File type: pdf · Size: 45271 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=recorder%20ensemble%20sheet%20music%20pdf, https://cdn.shopify.com/s/files/1/0500/5348/0611/files/ordinal_numbers_coloring_worksheet.pdf, https://cdn.shopify.com/s/files/1/0481/9648/5277/files/76455219599.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=recorder%20ensemble%20sheet%20music%20pdf
- https://s3.amazonaws.com/minaxigevani/annihilation_of_caste_by_ambedkar.pdf
- https://s3.amazonaws.com/rorives/histology_and_cytology.pdf
- https://s3.amazonaws.com/tadovu/runequest_glorantha_bestiary.pdf
- https://cdn.shopify.com/s/files/1/0500/5348/0611/files/ordinal_numbers_coloring_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0481/9648/5277/files/76455219599.pdf
- https://cdn.shopify.com/s/files/1/0498/2915/0882/files/gepobimaxavonavixaponoko.pdf
- https://cdn.shopify.com/s/files/1/0484/5597/5062/files/michael_tellinger_ubuntu_contributionism.pdf
- https://cdn-cms.f-static.net/uploads/4367633/normal_5f89b4e3e5e23.pdf
- https://cdn-cms.f-static.net/uploads/4387814/normal_5f9443171ea8f.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f87357c70f67.pdf
- https://cdn-cms.f-static.net/uploads/4371258/normal_5f95a8bb855f1.pdf
- https://s3.amazonaws.com/jamokaroxoj/78812881056.pdf
- https://s3.amazonaws.com/lixasifasi/factory_design_pattern_in_java.pdf
- https://s3.amazonaws.com/zuxadol/mumiwadamulisokub.pdf
- https://s3.amazonaws.com/duzexefemosaxe/buwutegolej.pdf
- https://s3.amazonaws.com/fenatagazise/arachis_pintoi.pdf
- https://kujiviremi.weebly.com/uploads/1/3/2/3/132302989/ravakeduzolofal-nerilojeta-simer-suwimagutijafij.pdf
- https://pixabetamomu.weebly.com/uploads/1/3/1/0/131070001/jumivum.pdf
- https://nadazeva.weebly.com/uploads/1/3/4/4/134499610/tulama_kokapomi_xukevomigif_xikokiba.pdf
- https://vurofagulomefu.weebly.com/uploads/1/3/1/4/131452840/ditaxegeke.pdf
- https://rikisuluwujufa.weebly.com/uploads/1/3/1/4/131452938/leguzolumoxofof.pdf
- https://uploads.strikinglycdn.com/files/a430cdbc-d3ea-4633-92db-a6a533ead284/xitelofimosoredufetunubek.pdf
- https://uploads.strikinglycdn.com/files/390a2c24-d1a3-4278-abde-ccb0f156d20d/achilles_tendon_stretches_for_runners.pdf
- https://uploads.strikinglycdn.com/files/33934b60-52db-4c24-9f0d-d73811b5d15f/38070220622.pdf
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- cdn-cms.f-static.net
- kujiviremi.weebly.com
- pixabetamomu.weebly.com
- nadazeva.weebly.com
- vurofagulomefu.weebly.com
- rikisuluwujufa.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report