SUSPICIOUS — 1472048.pdf
SUSPICIOUS — 1472048.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
917dd3542505a35f8679b470ff5a550738c0b711615184a062c8e84ba480157c - SHA-1:
ab4e91d609c06040008f6bebedadc7e505c37d54 - MD5:
40e4a17e9416c8e888724bf31f204c8a - ssdeep:
768:XgGzpDBp5g1z+nGSPJSGnJDfiI322SwF0JxeewbnQ/g3mKYa0vEAoFjt1gBlzqrH:wGFFpa9bDiRbnQo2KYa0vgwnzqGWR6w - TLSH:
T1DE317DF394ABEC4CBA8B9B03ADEB11996149D78A6177E7D01488772CC47C1AD7F20421 - Submitted as: 1472048.pdf
- File type: pdf · Size: 40295 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=stronghold%20crusader%202%20trainers, https://cdn-cms.f-static.net/uploads/4365551/normal_5f87186ae9983.pdf, https://cdn-cms.f-static.net/uploads/4365607/normal_5f8700ec65967.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=stronghold%20crusader%202%20trainers
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f87186ae9983.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f8700ec65967.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f870acc9dbb9.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f87786807314.pdf
- https://cdn.shopify.com/s/files/1/0433/7922/8837/files/47351175271.pdf
- https://site-1039494.mozfiles.com/files/1039494/nomubosida.pdf
- https://site-1043704.mozfiles.com/files/1043704/jakomatezitovax.pdf
- https://site-1039621.mozfiles.com/files/1039621/prime_and_composite_numbers_1-100_worksheets.pdf
- https://site-1038759.mozfiles.com/files/1038759/88820277349.pdf
- https://site-1038573.mozfiles.com/files/1038573/61027761727.pdf
- https://uploads.strikinglycdn.com/files/c6c65407-c815-47d1-8176-ce56417d34aa/56037775260.pdf
- https://uploads.strikinglycdn.com/files/78e827b8-ac83-4207-bfe1-8a3324165841/51114535118.pdf
- https://uploads.strikinglycdn.com/files/f93146d5-06ad-4440-b4c6-4ba5f83b553b/80600855354.pdf
- https://uploads.strikinglycdn.com/files/a8ff2f72-bc31-4fc6-9814-ce044d95ea1b/moxolarifabup.pdf
- https://uploads.strikinglycdn.com/files/d9227721-24e7-4b80-b4c8-ee824010db52/19424236851.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f877e6913ec5.pdf
- https://cdn-cms.f-static.net/uploads/4366627/normal_5f87849ab3fb7.pdf
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f87a4e625631.pdf
- https://site-1039386.mozfiles.com/files/1039386/kifurolugawiv.pdf
- https://site-1040223.mozfiles.com/files/1040223/83047872903.pdf
- https://site-1039378.mozfiles.com/files/1039378/gefiwonizifaw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1039494.mozfiles.com
- site-1043704.mozfiles.com
- site-1039621.mozfiles.com
- site-1038759.mozfiles.com
- site-1038573.mozfiles.com
- uploads.strikinglycdn.com
- site-1039386.mozfiles.com
- site-1040223.mozfiles.com
- site-1039378.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report