SUSPICIOUS — 54c45388de4e.pdf
SUSPICIOUS — 54c45388de4e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
e017416cf68638ede96380632ad6dd2e4d0b59f52684282af942949bfb1910a8 - SHA-1:
a4609c993b6c3e537c5673cb218b07a83ff3b69a - MD5:
d3afe00920693e87a71f10590291d815 - ssdeep:
768:egGzpDgepc1p2vmXKZbxCJ5igPdv6v46ari5r2ylJS6s71wZdp8+mp8UUi67M9bY:bGFEepYWrzMt1wJpMD56I9JqZlHh - TLSH:
T11432ADF31493ED8D7E8B9B83ACAB01A9648AD7882127979104CC3B9CC57C2BD7F50561 - Submitted as: 54c45388de4e.pdf
- File type: pdf · Size: 47389 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=divinity%20original%20sin%202%20zauberliste, https://uploads.strikinglycdn.com/files/0913c4b2-f0e6-4915-ad76-049a26e9c2c3/kerilumila.pdf, https://uploads.strikinglycdn.com/files/f7ef7c94-cf4d-4e07-b163-87c1169ad003/varakonazefepax.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=divinity%20original%20sin%202%20zauberliste
- https://uploads.strikinglycdn.com/files/0913c4b2-f0e6-4915-ad76-049a26e9c2c3/kerilumila.pdf
- https://uploads.strikinglycdn.com/files/f7ef7c94-cf4d-4e07-b163-87c1169ad003/varakonazefepax.pdf
- https://uploads.strikinglycdn.com/files/511d8c02-095a-43de-a006-0f73d21665bc/98596637708.pdf
- https://cdn.shopify.com/s/files/1/0492/5027/1388/files/blood_and_chocolate_book_free_download.pdf
- https://cdn.shopify.com/s/files/1/0478/0038/5695/files/cockneys_vs_zombies_parents_guide.pdf
- https://cdn.shopify.com/s/files/1/0497/5217/8849/files/delesonegufurevofanarorug.pdf
- https://cdn.shopify.com/s/files/1/0266/9704/0067/files/xelenupej.pdf
- https://cdn.shopify.com/s/files/1/0476/7996/3302/files/black_sports_and_entertainment_hall_of_fame.pdf
- https://cdn.shopify.com/s/files/1/0484/9667/2930/files/wapipe.pdf
- https://cdn.shopify.com/s/files/1/0499/8348/8160/files/32216063183.pdf
- https://cdn.shopify.com/s/files/1/0435/2815/9381/files/glencoe_california_mathematics_grade_6.pdf
- https://cdn.shopify.com/s/files/1/0496/1471/7095/files/chapter_3_from_farm_to_factory.pdf
- https://cdn.shopify.com/s/files/1/0434/5508/6742/files/minecraft_steve_costume_head.pdf
- https://cdn.shopify.com/s/files/1/0439/2547/1400/files/best_ticket_brokers.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f87d2ca1ab46.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f871688edf7c.pdf
- https://cdn-cms.f-static.net/uploads/4375087/normal_5f89f0af92671.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f8703358156b.pdf
- https://cdn.shopify.com/s/files/1/0266/7937/8108/files/bodenoduxosegazos.pdf
- https://cdn.shopify.com/s/files/1/0432/9095/1848/files/merge_files_review.pdf
- https://cdn.shopify.com/s/files/1/0492/0390/4676/files/23913293964.pdf
- https://cdn.shopify.com/s/files/1/0479/1163/3062/files/do_you_capitalize_native.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report