SUSPICIOUS — puludoje.pdf
SUSPICIOUS — puludoje.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a58d11f795e316b059a61df0dbf5c47367f9134269ee183864bafc3819739d06 - SHA-1:
460000b1758929a737c9a852f7bc71d838455a7d - MD5:
9fd838dff09c770db8e13fff87db1916 - ssdeep:
768:5rgGzpDMp2K5llXcJ/cHkI4y+4JmnkulHj+X5mN5XtBGjG9bQBgjn/8JqR+6:CGFop23YuBKpmN59BuG9SOn/2qR+6 - TLSH:
T10B328DF710A7EC4CBA4BAB53ADBA119C5489D788A03A979044DC7B3CC4BC5AD6F10960 - Submitted as: puludoje.pdf
- File type: pdf · Size: 46771 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=best%20free%20messaging%20apps%20for%20android, https://site-1036633.mozfiles.com/files/1036633/97925353862.pdf, https://site-1042985.mozfiles.com/files/1042985/donozidavilaxejujeno.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=best%20free%20messaging%20apps%20for%20android
- https://site-1036633.mozfiles.com/files/1036633/97925353862.pdf
- https://site-1042985.mozfiles.com/files/1042985/donozidavilaxejujeno.pdf
- https://site-1044164.mozfiles.com/files/1044164/jodiwolajotit.pdf
- https://site-1043154.mozfiles.com/files/1043154/subhash_kashyap_our_parliament_book.pdf
- https://site-1039675.mozfiles.com/files/1039675/14081506148.pdf
- https://cdn-cms.f-static.net/uploads/4368226/normal_5f8782320e4bf.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_5f8821ef2ef26.pdf
- https://uploads.strikinglycdn.com/files/2aba0123-8c06-4ab3-ba5e-5fe97869ccd2/20370570501.pdf
- https://uploads.strikinglycdn.com/files/9f906f74-3d2a-4131-a032-f622e4e44686/40332793991.pdf
- https://uploads.strikinglycdn.com/files/61ff7e4a-718b-4621-b2c7-5df69bcb737b/rukatitudiditozopariwusum.pdf
- https://uploads.strikinglycdn.com/files/294cf992-d814-479e-8555-b1c462bf714e/tozewexawitimisudebusasab.pdf
- https://cdn-cms.f-static.net/uploads/4367938/normal_5f87ec01449aa.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f8731ba78447.pdf
- https://cdn-cms.f-static.net/uploads/4366949/normal_5f875b140f1ca.pdf
- https://cdn-cms.f-static.net/uploads/4369150/normal_5f88080ed35aa.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f883eb0511e2.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f87116264ee9.pdf
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f881d631cea1.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f876a9999bc6.pdf
- https://cdn-cms.f-static.net/uploads/4369160/normal_5f87f33f8372f.pdf
- https://uploads.strikinglycdn.com/files/53713236-8615-4e91-a7b6-1b226ca7b412/19930710602.pdf
- https://uploads.strikinglycdn.com/files/a169f54e-d735-4fbd-8625-a5e15b8493ea/2121788808.pdf
- https://uploads.strikinglycdn.com/files/55cd2e35-7bda-4575-8553-a8fe661653b0/widijuweferuxerido.pdf
- https://uploads.strikinglycdn.com/files/867c70fe-fb52-4555-9583-bdff0f4435bc/20746773692.pdf
Embedded domains
- cctraff.ru
- site-1036633.mozfiles.com
- site-1042985.mozfiles.com
- site-1044164.mozfiles.com
- site-1043154.mozfiles.com
- site-1039675.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report