SUSPICIOUS — e5f17.pdf
SUSPICIOUS — e5f17.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
d2f8d2027908fd0e87a8b621e15374573c0d7bfe2195b2bf3ee0b67e3050b764 - SHA-1:
ab0a336f2bb19ce2d2194fe35783f44f87e7d35b - MD5:
e2bcc780bfc45cf31e15759a2ca2a276 - ssdeep:
768:pgGzpD7ek54wNR9Z5E4BX6Wd7QySsNVBjStMsP6oR:KGFXeKxXE837JVI6sP6oR - TLSH:
T119332AF33097DD4CA9C7AB4369AA20F970C5C24D712297900E58676CA4FB6BD7E30960 - Submitted as: e5f17.pdf
- File type: pdf · Size: 52202 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=exercice%20son%20in%20ain%20ein%20ce2, https://uploads.strikinglycdn.com/files/9de051ab-51d7-4b6a-9171-7a849909aeea/89329802846.pdf, https://uploads.strikinglycdn.com/files/79d1c37f-ea6d-4087-b343-eeeb5151131b/54264918966.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=exercice%20son%20in%20ain%20ein%20ce2
- https://uploads.strikinglycdn.com/files/9de051ab-51d7-4b6a-9171-7a849909aeea/89329802846.pdf
- https://uploads.strikinglycdn.com/files/79d1c37f-ea6d-4087-b343-eeeb5151131b/54264918966.pdf
- https://uploads.strikinglycdn.com/files/de87a234-fcfe-42d9-b88c-6ffaab67ae62/14721120638.pdf
- https://uploads.strikinglycdn.com/files/70310b81-c300-40e4-8930-ac1cf9e7353d/84346229115.pdf
- https://uploads.strikinglycdn.com/files/4d590933-f26b-4dfe-a0cf-bacc1d01d038/43562662426.pdf
- https://uploads.strikinglycdn.com/files/6d63704c-2f85-45dd-8173-ecb16fb2633d/zoxejivodisurikekerojujo.pdf
- https://uploads.strikinglycdn.com/files/e73610aa-d4e8-4876-b7bf-9f3c3f4f8244/57648034714.pdf
- https://uploads.strikinglycdn.com/files/5b3db37d-98d5-44d3-8332-5e6a1273ccb1/65138842569.pdf
- https://uploads.strikinglycdn.com/files/c343396a-ba78-4c03-a01e-48a1eab79cf7/92013636558.pdf
- https://uploads.strikinglycdn.com/files/c944043d-f918-4309-abab-b4c1f8195093/66024354288.pdf
- https://uploads.strikinglycdn.com/files/24598eae-5a22-466e-b4b5-f34d356c96b3/mijapu.pdf
- https://uploads.strikinglycdn.com/files/25824aca-b5c3-416c-9ef0-9fad42e9384e/50090415724.pdf
- https://uploads.strikinglycdn.com/files/4cd456da-1f4b-43d1-8caf-8e69d231783f/lirezejiromamovonopide.pdf
- https://uploads.strikinglycdn.com/files/2c220462-31c6-4939-bc4b-cf1305d80fb3/77766071739.pdf
- https://uploads.strikinglycdn.com/files/066af38a-417f-4197-8124-b0b4f751e734/pajavugupu.pdf
- https://site-1039490.mozfiles.com/files/1039490/37184200051.pdf
- https://site-1039149.mozfiles.com/files/1039149/81171916255.pdf
- https://site-1040250.mozfiles.com/files/1040250/vafarumibedatiziwogiruwix.pdf
- https://site-1039215.mozfiles.com/files/1039215/49035850896.pdf
- https://site-1043088.mozfiles.com/files/1043088/6988912285.pdf
- https://site-1043246.mozfiles.com/files/1043246/54214529189.pdf
- https://site-1044202.mozfiles.com/files/1044202/36038080524.pdf
- https://site-1038455.mozfiles.com/files/1038455/kunarexuvefudajudafo.pdf
- https://site-1043759.mozfiles.com/files/1043759/xelixikazimalolovewig.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1039490.mozfiles.com
- site-1039149.mozfiles.com
- site-1040250.mozfiles.com
- site-1039215.mozfiles.com
- site-1043088.mozfiles.com
- site-1043246.mozfiles.com
- site-1044202.mozfiles.com
- site-1038455.mozfiles.com
- site-1043759.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report