SUSPICIOUS — 5ed130.pdf
SUSPICIOUS — 5ed130.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
d2c278cabcdd59873436e2ca1c191a6f95206289f90da964b75dc88e200104ff - SHA-1:
8146e325975f19527291a2c97cd4085b8596dae7 - MD5:
3a9e4167acf87de7f377ed4229317520 - ssdeep:
768:BgGzpDpejBS+k9PStwo9lk6x4CL4yZU6Y4RQxPtQcUEiOMf4/NVj3+grf:yGFNeLtEW4yZI4+xPtQ0o4/NVygrf - TLSH:
T1EA328EF31093ED8C7A8B5F13ADB6146E608ED38C613697900588362DC5BC6BE7E40A75 - Submitted as: 5ed130.pdf
- File type: pdf · Size: 46889 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=computer%20shutdown%20without%20warning, https://site-1039528.mozfiles.com/files/1039528/25399128885.pdf, https://site-1036957.mozfiles.com/files/1036957/tadufitibusik.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=computer%20shutdown%20without%20warning
- https://site-1039528.mozfiles.com/files/1039528/25399128885.pdf
- https://site-1036957.mozfiles.com/files/1036957/tadufitibusik.pdf
- https://site-1040998.mozfiles.com/files/1040998/biwiwagofajalofasuw.pdf
- https://site-1039273.mozfiles.com/files/1039273/37573810175.pdf
- https://uploads.strikinglycdn.com/files/c7c94268-47df-4876-a711-468270f7ac1d/damireniziwepoxulepu.pdf
- https://uploads.strikinglycdn.com/files/6ec63e75-af2a-4f9e-98a3-ef1fb1fe0931/tojifi.pdf
- https://uploads.strikinglycdn.com/files/e65f6560-1042-4c59-9dae-2b38f0ebbed3/31864965318.pdf
- https://uploads.strikinglycdn.com/files/7cdeeb30-e2f8-405c-b042-8a3aa4f40e04/dolojozusiwobolatikokawow.pdf
- https://uploads.strikinglycdn.com/files/0d5d0930-f3e3-4b1b-bb30-2e60d3aca9d4/92889619633.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f871c86e660a.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f870f3bc053d.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f882b215f419.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f87179d0ba82.pdf
- https://nipaxibovaj.weebly.com/uploads/1/3/1/3/131379211/beroselalom.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/pejajofedaxevaw_kozadesupuke.pdf
- https://zozilevijuni.weebly.com/uploads/1/3/1/3/131383476/4262709.pdf
- https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/502577.pdf
- https://worobewunit.weebly.com/uploads/1/3/1/4/131406731/ceef4e9.pdf
- https://fanawilixu.weebly.com/uploads/1/3/1/4/131408209/2532419.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/dinisepomuzejekeged.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f870b1b0a7b7.pdf
- https://cdn-cms.f-static.net/uploads/4370768/normal_5f881cfb210df.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f87e3d4e2145.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- site-1039528.mozfiles.com
- site-1036957.mozfiles.com
- site-1040998.mozfiles.com
- site-1039273.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- nipaxibovaj.weebly.com
- guwomenod.weebly.com
- zozilevijuni.weebly.com
- mijisurux.weebly.com
- worobewunit.weebly.com
- fanawilixu.weebly.com
- nudojafobedem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report