SUSPICIOUS — 2914966.pdf
SUSPICIOUS — 2914966.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a3809fcb12bdbda140ad9b5e972724083e369d6608dda3745262b99e37533c52 - SHA-1:
9335f5ca5c19095d451f25ca485f1e78cb2b386e - MD5:
7d9e3f71404c2d8c253156a4477bc3f1 - ssdeep:
1536:3QGFLp+8eV0ximAMxaqiRFVBqvTJJDAGDSX0hfRMSs3uW:NFLp+8HzuBgDAdWsz - TLSH:
T11C339EF310A7ED8D6A4B6F17ADA7116DA48EC64D602697A009CC572CC0FCAFD7E00A51 - Submitted as: 2914966.pdf
- File type: pdf · Size: 51508 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=born%20a%20crime:%20stories%20from%20a%20south%20a, https://cdn-cms.f-static.net/uploads/4366973/normal_5f8a001f64ca2.pdf, https://cdn-cms.f-static.net/uploads/4365584/normal_5f87c66f96c44.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=born%20a%20crime:%20stories%20from%20a%20south%20a
- https://cdn-cms.f-static.net/uploads/4366973/normal_5f8a001f64ca2.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f87c66f96c44.pdf
- https://cdn-cms.f-static.net/uploads/4374953/normal_5f8bed9d873db.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f86ff7f5106d.pdf
- https://uploads.strikinglycdn.com/files/036ba314-093f-40c1-b299-f82f80602fef/55971481510.pdf
- https://uploads.strikinglycdn.com/files/4f0473ca-239d-4b98-b001-85a5c5285446/nypd_red_alert.pdf
- https://uploads.strikinglycdn.com/files/2595ac74-c2cc-4185-9248-83fc18841654/53345733538.pdf
- https://uploads.strikinglycdn.com/files/b187b49f-30f1-49c8-b0f6-103a31c109f9/feburusevepaf.pdf
- https://uploads.strikinglycdn.com/files/bbfa8644-9f38-4e7d-b1d8-c1892230a76b/22923537248.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f86febcba19b.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f89e63f62852.pdf
- https://cdn-cms.f-static.net/uploads/4367305/normal_5f8763d063381.pdf
- https://gonerogad.weebly.com/uploads/1/3/1/4/131438616/tiviwisomevenu.pdf
- https://pimetagedipimop.weebly.com/uploads/1/3/1/6/131636886/fedabolitode-suduxonepowomo-sigidutipiwikew-pelilamom.pdf
- https://ganulexotugoris.weebly.com/uploads/1/3/1/1/131164012/7245916.pdf
- https://uploads.strikinglycdn.com/files/8787fa7d-949b-4192-ae95-bd9f4ed05349/22120922633.pdf
- https://uploads.strikinglycdn.com/files/d6cc5a0f-ce17-45e3-b5d9-81c6f1193adb/75895748833.pdf
- https://uploads.strikinglycdn.com/files/9dfb03de-4dc5-4545-8db3-893a65e30b3a/42802832197.pdf
- https://uploads.strikinglycdn.com/files/5a38d79a-4215-4edd-be79-74f97dfb12e1/novena_de_aguinaldos_en_ingles.pdf
- https://uploads.strikinglycdn.com/files/aa18efed-b0d6-4437-bf1e-3f4b950068bf/natapixizisoxuguzize.pdf
- https://cdn-cms.f-static.net/uploads/4370304/normal_5f889a56e8b51.pdf
- https://cdn-cms.f-static.net/uploads/4382193/normal_5f8bf78d79aab.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f8891c32778a.pdf
- https://cdn-cms.f-static.net/uploads/4370059/normal_5f8a6564c0050.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- gonerogad.weebly.com
- pimetagedipimop.weebly.com
- ganulexotugoris.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report