SUSPICIOUS — c3b9d17.pdf
SUSPICIOUS — c3b9d17.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b94c548d350c11680a461da9eee292bfd74491b492585b84c6c1e148294951a8 - SHA-1:
0c9bd80789adb50cb9693d71876c8ba24c663de6 - MD5:
3eb6f812882395f29f7818cf8ccd6282 - ssdeep:
1536:DGFVpE7kIy2dA0F5VtrOoA+NfbSQwVlfW/RrmI:SFVpE762q+zr4+NfbaVlGn - TLSH:
T1B3348CF310A7EC4C3B9B6B03AEAB1199518AD3496137D7A0418C776CD4BC7EE2E01A51 - Submitted as: c3b9d17.pdf
- File type: pdf · Size: 53112 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=persona%20q%20quest%20guide, https://uploads.strikinglycdn.com/files/c3b47f01-79bd-465c-ab56-fe5db188f12d/22306793632.pdf, https://uploads.strikinglycdn.com/files/4b4272ab-f43e-4a50-a6e8-326ffb40d6b0/sekusowa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=persona%20q%20quest%20guide
- https://uploads.strikinglycdn.com/files/c3b47f01-79bd-465c-ab56-fe5db188f12d/22306793632.pdf
- https://uploads.strikinglycdn.com/files/4b4272ab-f43e-4a50-a6e8-326ffb40d6b0/sekusowa.pdf
- https://uploads.strikinglycdn.com/files/43b5c4ac-8758-4db4-8ccd-0a07db04687f/dulfy_mursaat_token.pdf
- https://uploads.strikinglycdn.com/files/9b27c5d9-e61d-423a-9c26-ee6ce4785bda/gakofew.pdf
- https://uploads.strikinglycdn.com/files/9c487a12-9326-4ba5-b099-3917562bc8e2/75459784701.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/threatening_with_a_bladed_article_sentencing_guidelines.pdf
- https://cdn.shopify.com/s/files/1/0434/2536/6165/files/27986659297.pdf
- https://cdn.shopify.com/s/files/1/0460/4048/1956/files/body_by_jake_tower_200.pdf
- https://cdn-cms.f-static.net/uploads/4372101/normal_5f8ccbeca6c11.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f88b0af4cfcc.pdf
- https://cdn-cms.f-static.net/uploads/4378831/normal_5f8b21952946e.pdf
- https://uploads.strikinglycdn.com/files/b1400451-a45d-419f-ae7c-754f11903d00/23295835567.pdf
- https://uploads.strikinglycdn.com/files/303395c6-ad1f-46d4-b373-1496a7b51360/fugonozofexalubadetepijof.pdf
- https://uploads.strikinglycdn.com/files/b8475418-9621-4c79-bbb1-0b9ff1c067d2/detufuliwatigigewebogok.pdf
- https://uploads.strikinglycdn.com/files/7e17d3fb-e21e-4536-9b00-f70e7a6d2d78/heart_of_the_guardian_kotor.pdf
- https://uploads.strikinglycdn.com/files/29ce2c57-81fe-4f6a-afae-ec9269b96be4/40762568600.pdf
- https://uploads.strikinglycdn.com/files/4cee1e74-22a5-4ea9-84d9-c43e226df330/rukodu.pdf
- https://uploads.strikinglycdn.com/files/d161dc4c-c3d3-449c-a2f7-a12dde261f5b/duzisopunafemal.pdf
- https://uploads.strikinglycdn.com/files/369a1716-d7fe-4c30-87c7-02ec05c0dffa/cherry_valley_waterbury_ct.pdf
- https://uploads.strikinglycdn.com/files/9d8fc211-1d79-4b37-9a08-e748b0d1bf39/52887131421.pdf
- https://uploads.strikinglycdn.com/files/afbf1ddd-9085-46d2-846f-580a74d37106/nuserusodakefezuloxoru.pdf
- https://uploads.strikinglycdn.com/files/f0595cd6-b04a-4ddf-80ed-a19c9a495734/muwoluwuribeke.pdf
- https://uploads.strikinglycdn.com/files/cd670a5a-0a12-4724-ab42-4ac4aee9da03/textos_em_caderno_de_caligrafia.pdf
- https://uploads.strikinglycdn.com/files/c7822012-fc0b-4558-b6a0-7c212e19ed2c/lazomaloveverikuvavukago.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report