SUSPICIOUS — 2021312.pdf
SUSPICIOUS — 2021312.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e4c0671f8a3bbba97d70275651bbdfe8651e8b9fd3ce76777d4593c7214361ff - SHA-1:
8887fff5f56eebaf7564c0e56f2c38389a62e337 - MD5:
572125da1627e5a03edcf5a756040828 - ssdeep:
1536:jGF3pw7+KYhtLNcpje3dnXVogRDP5otZT:yF3pwiKYh5NcpjodnXegRDaH - TLSH:
T19C339DF32097EC4DBA87AF13ADBB1655918AC64CA2369750595C633CC0BC27E7F10861 - Submitted as: 2021312.pdf
- File type: pdf · Size: 50974 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=battle%20of%20ramelle, https://cdn.shopify.com/s/files/1/0500/3785/0262/files/pic_collage_with_video_app_for_android.pdf, https://cdn.shopify.com/s/files/1/0438/4640/2198/files/goblin_ranger_names.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=battle%20of%20ramelle
- https://s3.amazonaws.com/fasanag/41837712795.pdf
- https://s3.amazonaws.com/sugaguxagu/belajar_bahasa_korea_pemula.pdf
- https://s3.amazonaws.com/wonoti/37037835112.pdf
- https://s3.amazonaws.com/tadovu/jukegox.pdf
- https://cdn.shopify.com/s/files/1/0500/3785/0262/files/pic_collage_with_video_app_for_android.pdf
- https://cdn.shopify.com/s/files/1/0438/4640/2198/files/goblin_ranger_names.pdf
- https://cdn.shopify.com/s/files/1/0432/1709/2769/files/jonobibajefegazumerupemed.pdf
- https://cdn.shopify.com/s/files/1/0439/4532/8808/files/fumejarexetozomakowa.pdf
- https://cdn.shopify.com/s/files/1/0500/7107/7027/files/converting_grams_to_moles_worksheet_answers.pdf
- https://cdn-cms.f-static.net/uploads/4378149/normal_5f8f1ab87db07.pdf
- https://cdn-cms.f-static.net/uploads/4366637/normal_5f8fc65a5e17d.pdf
- https://cdn-cms.f-static.net/uploads/4375896/normal_5f8f2451e7adf.pdf
- https://cdn-cms.f-static.net/uploads/4378161/normal_5f8bbde0a343e.pdf
- https://cdn-cms.f-static.net/uploads/4379987/normal_5f8c65c941093.pdf
- https://cdn-cms.f-static.net/uploads/4367304/normal_5f8769b4d10c6.pdf
- https://cdn-cms.f-static.net/uploads/4366630/normal_5f875e2b933f2.pdf
- https://cdn-cms.f-static.net/uploads/4366993/normal_5f8c657664d7b.pdf
- https://cdn-cms.f-static.net/uploads/4368777/normal_5f8e18e689c18.pdf
- https://cdn.shopify.com/s/files/1/0433/5996/1247/files/sifuj.pdf
- https://cdn.shopify.com/s/files/1/0499/2188/4328/files/avg_vpn_apk_cracked.pdf
- https://s3.amazonaws.com/gupuso/fizofugofiberemej.pdf
- https://s3.amazonaws.com/tetazino/xegozatikinajevumerewa.pdf
- https://s3.amazonaws.com/felasorarabipis/maths_formulas_for_class_12_science.pdf
- https://s3.amazonaws.com/wonoti/bomanomabepagakujijired.pdf
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report