SUSPICIOUS — 2801018.pdf
SUSPICIOUS — 2801018.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
aaf2d9b459dc177c6032d1bb1d9e6358d581f527d09939d4b4995f18434e28a2 - SHA-1:
84d652df6664d6079a9b98c1009c681adab54361 - MD5:
09180a36a0d51c4bbb1a5d2fbc08b528 - ssdeep:
768:GgGzpD8pvkhS4kxnBIlhahjwQTgqufIcGyJnWSDs/A8tvoICB:TGFYpaMnMha5wQTgqQJi/TtvoICB - TLSH:
T1C4307CF34493DD8C7A979B83AEA62585608AC6CD7132966014C8377CC5BC2FDBF109A1 - Submitted as: 2801018.pdf
- File type: pdf · Size: 37542 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=jamajsk%C3%A1%20Hudba%20Zdarma%20mp3%20ke%20sta%C5%BEen%C3%AD, https://site-1041939.mozfiles.com/files/1041939/spyware_app_for_android_free.pdf, https://site-1037219.mozfiles.com/files/1037219/56596756304.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=jamajsk%C3%A1%20Hudba%20Zdarma%20mp3%20ke%20sta%C5%BEen%C3%AD
- https://site-1041939.mozfiles.com/files/1041939/spyware_app_for_android_free.pdf
- https://site-1037219.mozfiles.com/files/1037219/56596756304.pdf
- https://site-1037074.mozfiles.com/files/1037074/sabulutuzupol.pdf
- https://site-1038979.mozfiles.com/files/1038979/24048190451.pdf
- https://cdn.shopify.com/s/files/1/0485/1112/3611/files/nuvuwobusamegabovenoda.pdf
- https://cdn.shopify.com/s/files/1/0434/1992/6679/files/diablo_2_free_download_reddit.pdf
- https://cdn.shopify.com/s/files/1/0441/0900/4952/files/fezijedezam.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/e9ff54.pdf
- https://ridolagu.weebly.com/uploads/1/3/0/7/130775195/difusalabefe-kisoget.pdf
- https://uploads.strikinglycdn.com/files/ef9f1de1-24a8-4989-a573-3528e8344eee/6373624488.pdf
- https://uploads.strikinglycdn.com/files/58bac5c0-88fa-4f8b-98da-10bc13ea05c4/viwexeziposidelogat.pdf
- https://uploads.strikinglycdn.com/files/7111c037-a03c-4a6f-8bb5-3befe8efe565/nefanokalelotogi.pdf
- https://site-1044197.mozfiles.com/files/1044197/ruranutibove.pdf
- https://site-1039829.mozfiles.com/files/1039829/davoki.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/c5bcf5e47.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/wogiselaruto-nokage.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/nukunuraki.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- https://play.google.com/store/apps/details
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- site-1041939.mozfiles.com
- site-1037219.mozfiles.com
- site-1037074.mozfiles.com
- site-1038979.mozfiles.com
- cdn.shopify.com
- fodezamu.weebly.com
- ridolagu.weebly.com
- uploads.strikinglycdn.com
- site-1044197.mozfiles.com
- site-1039829.mozfiles.com
- sepikupi.weebly.com
- xojerajap.weebly.com
- dutitujazekap.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- play.google.com
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report