SUSPICIOUS — 54e7a3.pdf
SUSPICIOUS — 54e7a3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
80502845289c97a110813bf1242e5306f0696672f9ae87dbed20a3d9ec7614d2 - SHA-1:
9350f6de97667e9c31601ec83f49a5f31dafd5b3 - MD5:
784ede312188e5f7d5e2b357fd3edbb6 - ssdeep:
768:pPgGzpDbp4myRsvBS1EKWcV9VQFgZlDIZhG5Gvhnm5C8HuE95NF/T:iGFXpT69USl5QJnmoA5NF/T - TLSH:
T174328EF320B7EE4C7A87EF439DAA259CA049E788617297A04598372CC47C27D7F40925 - Submitted as: 54e7a3.pdf
- File type: pdf · Size: 44436 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=cours%20hydraulique%20de%20base, https://uploads.strikinglycdn.com/files/dfccb256-4eab-4efe-85cd-cdb361a7c0d8/wezosobedazosoworujezo.pdf, https://uploads.strikinglycdn.com/files/a78f1184-2d0b-4006-85e2-2c863a32123e/50556524000.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=cours%20hydraulique%20de%20base
- https://uploads.strikinglycdn.com/files/dfccb256-4eab-4efe-85cd-cdb361a7c0d8/wezosobedazosoworujezo.pdf
- https://uploads.strikinglycdn.com/files/a78f1184-2d0b-4006-85e2-2c863a32123e/50556524000.pdf
- https://uploads.strikinglycdn.com/files/62107030-09fc-44a2-ac7f-13a7d102bb36/42839753898.pdf
- https://uploads.strikinglycdn.com/files/3271dbca-f3c5-4415-bd80-93d2eb79416b/24227789409.pdf
- https://uploads.strikinglycdn.com/files/ac44876b-792a-44e3-a51a-e53be8c84050/35080401817.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f872e3527d5f.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f86f8a0723a3.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f870f9043b17.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f8715853dff2.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f86f5eb69511.pdf
- https://uploads.strikinglycdn.com/files/9b5dd5a7-0445-48b1-aa82-825039101a15/91694794977.pdf
- https://uploads.strikinglycdn.com/files/946d046a-4f9f-4ed0-aae9-55bfe5c84ed2/66681124294.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/vigirupiruwovilav.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/297c0.pdf
- https://site-1041082.mozfiles.com/files/1041082/97305431998.pdf
- https://site-1040386.mozfiles.com/files/1040386/misurapusetuzixit.pdf
- https://site-1040178.mozfiles.com/files/1040178/75432765020.pdf
- https://site-1048176.mozfiles.com/files/1048176/4102088140.pdf
- https://site-1036993.mozfiles.com/files/1036993/molofojuxosavidix.pdf
- https://cdn.shopify.com/s/files/1/0266/7718/2646/files/the_great_compromise_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0498/1089/9099/files/56833394594.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- dutitujazekap.weebly.com
- guwomenod.weebly.com
- site-1041082.mozfiles.com
- site-1040386.mozfiles.com
- site-1040178.mozfiles.com
- site-1048176.mozfiles.com
- site-1036993.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report