SUSPICIOUS — sugawen.pdf
SUSPICIOUS — sugawen.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
dc7c49f1ef09695f815d44101e8229c564ae82355102ac8991755bef57a809be - SHA-1:
a2298830f0710e1e0a3dc6abdd7369530f21bf47 - MD5:
5431ebbab33e8a345314f5ad9bb11a8d - ssdeep:
1536:mGFEdnelDg1Yzy4ciAOsMlr1KeCcTzjzz65ixF0:/FEEvycAOsM11KEjzzKiY - TLSH:
T10733AEF750DBEC4C7A8E9B039EEA105A518AC3887132DB6405DCBA3DC4BC6AD7D11560 - Submitted as: sugawen.pdf
- File type: pdf · Size: 51686 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=accountancy%20class%2011%20ncert%20pdf, https://uploads.strikinglycdn.com/files/024b6ed2-9c43-4dd4-90e1-9f2b068ad0f3/49222777493.pdf, https://uploads.strikinglycdn.com/files/6889d927-57c2-4f89-b5c8-64e97e026584/1082063905.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=accountancy%20class%2011%20ncert%20pdf
- https://uploads.strikinglycdn.com/files/024b6ed2-9c43-4dd4-90e1-9f2b068ad0f3/49222777493.pdf
- https://uploads.strikinglycdn.com/files/6889d927-57c2-4f89-b5c8-64e97e026584/1082063905.pdf
- https://uploads.strikinglycdn.com/files/a63bdc1c-9690-4e11-81af-bc9a6f3be8db/nelumabe.pdf
- https://uploads.strikinglycdn.com/files/fc87e4a6-436c-49e8-902a-b6c94fdd6a62/7880586086.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/bokaxafixizan-wakodoxabuwo-tebamimisak.pdf
- https://kusebedanosude.weebly.com/uploads/1/3/1/1/131163667/8078414.pdf
- https://morurotefat.weebly.com/uploads/1/3/4/3/134317018/0d8ebcb.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/zagep-sewezaj-dubusufix-neguwimaratozad.pdf
- https://cdn.shopify.com/s/files/1/0486/6424/8470/files/honeywell_water_heater_thermostat_instructions.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/40234285809.pdf
- https://uploads.strikinglycdn.com/files/abc529ad-e46e-45ce-938e-1a8dd80c1d35/75709391243.pdf
- https://uploads.strikinglycdn.com/files/f186cc7f-d89f-47bf-b2dc-85f7762b3dbe/baby_driver_theater.pdf
- https://uploads.strikinglycdn.com/files/988259a7-760f-4901-83c0-9f0beebe76b3/samilokebuxa.pdf
- https://uploads.strikinglycdn.com/files/5aeb5e49-5101-47bf-8698-f9fb37c0c0e2/35750430664.pdf
- https://uploads.strikinglycdn.com/files/8462dfc0-e5dd-4bdb-a679-f5d49ec66747/runescape_3_f2p_smithing_guide.pdf
- https://penulikadima.weebly.com/uploads/1/3/1/4/131482887/jetugapop.pdf
- https://xubuvene.weebly.com/uploads/1/3/1/3/131380433/7fbea02c8e18a5e.pdf
- https://fidevawane.weebly.com/uploads/1/3/0/8/130814252/728af.pdf
- https://cdn-cms.f-static.net/uploads/4403531/normal_5f94aa7fd7677.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f89626ce2711.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- pumowurunumig.weebly.com
- kusebedanosude.weebly.com
- morurotefat.weebly.com
- sokuvotaboraj.weebly.com
- cdn.shopify.com
- penulikadima.weebly.com
- xubuvene.weebly.com
- fidevawane.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report