SUSPICIOUS — 18d31b0f8f3088.pdf
SUSPICIOUS — 18d31b0f8f3088.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c8d75380ea33f0dd079aee03f9a356252b9b82f272acf4df94d0f52b922c5b8c - SHA-1:
7951b219f29332cdf028064f09fe8d02c34333e4 - MD5:
053c60b3794ac4ca2c181eef984aec52 - ssdeep:
768:skgGzpD9YkDMtTImYldczPN+NWbHkcsiXatRSl7m8zmTk6GNm9eiBF:0GF5YwczPNZeiXCSZX6TkVmYiBF - TLSH:
T103328DF35097EE4C798B9F879EA6159D654AC3482132A7A0548CB72DC4F82FD3F00962 - Submitted as: 18d31b0f8f3088.pdf
- File type: pdf · Size: 45108 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=osteopathic%20manual%20practitioner%20salary, https://uploads.strikinglycdn.com/files/3903909b-19de-4c26-8cd5-f2913cdaa3f8/kof_98_um_ol_gift_code.pdf, https://wozofawado.weebly.com/uploads/1/3/0/8/130874325/tudozuputipupij.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=osteopathic%20manual%20practitioner%20salary
- https://uploads.strikinglycdn.com/files/3903909b-19de-4c26-8cd5-f2913cdaa3f8/kof_98_um_ol_gift_code.pdf
- https://s3.amazonaws.com/voxazedisula/android_api_documentation_download.pdf
- https://s3.amazonaws.com/jumedemimo/kagekimu.pdf
- https://wozofawado.weebly.com/uploads/1/3/0/8/130874325/tudozuputipupij.pdf
- https://cdn-cms.f-static.net/uploads/4368770/normal_5f93a4d59653f.pdf
- https://uploads.strikinglycdn.com/files/e227ed49-7d4f-44ce-a9e2-a497213940b4/10556650249.pdf
- https://zevigetadafuwun.weebly.com/uploads/1/3/0/9/130969942/747957.pdf
- https://cdn-cms.f-static.net/uploads/4379614/normal_5f8f6836189bb.pdf
- https://cdn-cms.f-static.net/uploads/4368999/normal_5f8aeb8c8815c.pdf
- https://uploads.strikinglycdn.com/files/0d8ae004-a733-4f22-ba66-fba037dd77f4/92804036738.pdf
- https://uploads.strikinglycdn.com/files/e875f1a0-f55a-43dd-aded-fcb09ed1a380/strength_of_materials_civil_objective_questions_and_answers.pdf
- https://uploads.strikinglycdn.com/files/ae04c0a3-099b-4ddc-bf7e-1d22998042b8/55809947706.pdf
- https://uploads.strikinglycdn.com/files/fcb4e29d-371d-4d42-b4d7-f9f9217e75d1/31854480263.pdf
- https://uploads.strikinglycdn.com/files/ad5a6091-5267-498a-a3f9-0dfd612e5754/78708628025.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/6390301.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f9055212bfd4.pdf
- https://uploads.strikinglycdn.com/files/194adbed-b6df-4da8-91cd-f60123d9e00f/retozojapelaf.pdf
- https://uploads.strikinglycdn.com/files/b587d290-4241-42d7-a804-81959bcbfc2c/l_ordinateur_et_ses_peripheriques.pdf
- https://gowiwoniba.weebly.com/uploads/1/3/1/8/131857243/1865409.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- wozofawado.weebly.com
- cdn-cms.f-static.net
- zevigetadafuwun.weebly.com
- natizupasa.weebly.com
- gowiwoniba.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report