SUSPICIOUS — 12898e59dfad6.pdf
SUSPICIOUS — 12898e59dfad6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ab55ee8003a1651857ffab96941d3186f68d12f95cc17f9c87eb04158f53a038 - SHA-1:
57c03dcf656d891eb18251769b15dcf66bca2fbf - MD5:
934cf5d77c3cb855a57374fb4b3a88fd - ssdeep:
1536:zGF6p7suYatwZJckilRUbA1i4uI0ROxFDHGKfyTLi6fRhzAJk:CF6p7svaiZJckijUboiuEUGK9oLX - TLSH:
T15B35CFF344D7ED8C7B46BB53A9BA1099568BD389603B93A404CC776DC8BC1BCAE00560 - Submitted as: 12898e59dfad6.pdf
- File type: pdf · Size: 62567 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=crepusculo%20libro%20pdf%20ingles, https://uploads.strikinglycdn.com/files/1ec46d94-856a-495e-91bd-25ed753a56f9/analisis_de_la_variacion_de_funciones.pdf, https://uploads.strikinglycdn.com/files/e784f04c-68fb-444e-bb3d-8404ef326c48/67564480098.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=crepusculo%20libro%20pdf%20ingles
- https://uploads.strikinglycdn.com/files/1ec46d94-856a-495e-91bd-25ed753a56f9/analisis_de_la_variacion_de_funciones.pdf
- https://uploads.strikinglycdn.com/files/e784f04c-68fb-444e-bb3d-8404ef326c48/67564480098.pdf
- https://uploads.strikinglycdn.com/files/92b4b0b2-4c8f-492f-bc7e-374363526337/74431868357.pdf
- https://uploads.strikinglycdn.com/files/1dd3cc03-f748-4b4d-bb48-995c7fd1236d/free_3_digit_addition_worksheets_without_regrouping.pdf
- https://uploads.strikinglycdn.com/files/6382e0d9-3d47-4a22-9fc1-92ff1a8f49eb/melugogosokolezun.pdf
- https://uploads.strikinglycdn.com/files/e9684899-f31f-4d65-9c4b-8e63fd55c396/35851387074.pdf
- https://uploads.strikinglycdn.com/files/d0093ee5-e98a-49d0-bea3-05ee12d6c57e/kuzuravopijexu.pdf
- https://uploads.strikinglycdn.com/files/193c9e7e-1a5c-43ad-86c8-2f6846ea4361/koxobutolawojakalok.pdf
- https://uploads.strikinglycdn.com/files/5f7b901e-57eb-4da1-90bc-cadc13724a34/fovop.pdf
- https://uploads.strikinglycdn.com/files/f0054b5d-a7be-42fd-a74a-1441fede1c5a/42256644654.pdf
- https://uploads.strikinglycdn.com/files/dc33c713-0d9e-442b-9f24-9616d9699c5c/lubipofa.pdf
- https://uploads.strikinglycdn.com/files/cffaadb7-bc88-4abd-a065-3cfdd2c6a2c6/zexomemos.pdf
- https://uploads.strikinglycdn.com/files/e0f8866a-b323-495c-9846-b2c13d17c280/37088840234.pdf
- https://uploads.strikinglycdn.com/files/189a4cd0-e0b4-4a9b-a739-7fa3193f6d28/lobokukotiluwisi.pdf
- https://uploads.strikinglycdn.com/files/312c853e-b020-416f-8b7b-ec1bad151707/livuletofonanefuzosaben.pdf
- https://cdn-cms.f-static.net/uploads/4369919/normal_5f89220ddd668.pdf
- https://cdn-cms.f-static.net/uploads/4372087/normal_5f8aa859da5e1.pdf
- https://uploads.strikinglycdn.com/files/554c25a3-2840-4a8a-86cf-549f156f18df/dagoxawafilazapijuli.pdf
- https://uploads.strikinglycdn.com/files/bdfb2706-60de-47f0-ba27-e274d6b17d7d/5182988780.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report