SUSPICIOUS — 5145362.pdf
SUSPICIOUS — 5145362.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
af3d24e34d3618be25069cb77a82ea5c2afdc377c94798268955512b6ebeaf5e - SHA-1:
7296a31d37630b524603263cdaca9820e18c106c - MD5:
6ce0c6d0ec6c3f1a9f992cbe4e7ade88 - ssdeep:
768:fgGzpD9p/Toc9clG26296N+42+BU8W7U8ZtOWrHVoX5X7TNwmJjl:oGFRpC64J+BXoOKVM5rSmJjl - TLSH:
T15D319EF325D7DE8C7E87AB17A9AA10A86089D38D613397A044DCB61CC47C6ED7E10461 - Submitted as: 5145362.pdf
- File type: pdf · Size: 42540 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=best%20java%20ide, https://cdn-cms.f-static.net/uploads/4366336/normal_5f87cac8b3550.pdf, https://cdn-cms.f-static.net/uploads/4366398/normal_5f88035ff3f32.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=best%20java%20ide
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f87cac8b3550.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f88035ff3f32.pdf
- https://cdn-cms.f-static.net/uploads/4367286/normal_5f882ff77a6aa.pdf
- https://uploads.strikinglycdn.com/files/2855f11f-3eac-4005-9418-3b4dac4d2fdd/78996375954.pdf
- https://uploads.strikinglycdn.com/files/5a901c34-c1a8-4c42-a3a8-e9413aa79423/dumemirifepoj.pdf
- https://uploads.strikinglycdn.com/files/6f34c89c-390b-4c2d-ba9a-2c6ad84dd133/99972585212.pdf
- https://site-1038779.mozfiles.com/files/1038779/tabejabojujirerodilig.pdf
- https://site-1040056.mozfiles.com/files/1040056/90552372050.pdf
- https://cdn-cms.f-static.net/uploads/4369308/normal_5f87b19ea4913.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f8719e879df6.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f87161934eab.pdf
- https://cdn-cms.f-static.net/uploads/4368972/normal_5f881fb8f1952.pdf
- https://uploads.strikinglycdn.com/files/14fb2681-581c-4e59-8b9e-f26894fac79f/takojuwojukinire.pdf
- https://uploads.strikinglycdn.com/files/443dc40c-66f7-47d5-824e-e3dc5bd57a0a/losuginememubip.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038779.mozfiles.com
- site-1040056.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report