SUSPICIOUS — banifif_bavasavazasa.pdf
SUSPICIOUS — banifif_bavasavazasa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
f36d999c61779d2b578b07ebdb1e7e34858c45e09ba396cf932de11e85569d60 - SHA-1:
70828674a4d929fbca0898bb4916dac5f139662f - MD5:
603ae5cce56a31c9ba69bdccda5245ec - ssdeep:
768:1gGzpD+2FhdDJIRpouh2TGe60gdbAQf6iUjU7Zog29awShYPgptT:mGF6ggVAQCiUjuZqtgptT - TLSH:
T17E329FF31197ED4C7A8B9F17ADAE246D948AD7886132A7A084CC672CD17C7AD3F00950 - Submitted as: banifif_bavasavazasa.pdf
- File type: pdf · Size: 47266 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=astera%20helios%20tube%20manual, https://cdn-cms.f-static.net/uploads/4402280/normal_5f90aae50f3bf.pdf, https://cdn-cms.f-static.net/uploads/4373797/normal_5f8a2be120d24.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=astera%20helios%20tube%20manual
- https://cdn-cms.f-static.net/uploads/4402280/normal_5f90aae50f3bf.pdf
- https://cdn-cms.f-static.net/uploads/4373797/normal_5f8a2be120d24.pdf
- https://cdn-cms.f-static.net/uploads/4374979/normal_5f89bf981c697.pdf
- https://cdn-cms.f-static.net/uploads/4391037/normal_5f924beac197f.pdf
- https://cdn-cms.f-static.net/uploads/4370547/normal_5f911d708879e.pdf
- https://cdn-cms.f-static.net/uploads/4375340/normal_5f8d0f611fa24.pdf
- https://cdn-cms.f-static.net/uploads/4379217/normal_5f9355a53e3ee.pdf
- https://cdn-cms.f-static.net/uploads/4366620/normal_5f877533e0c03.pdf
- https://cdn-cms.f-static.net/uploads/4373757/normal_5f8e0b9cbe07d.pdf
- https://cdn.shopify.com/s/files/1/0481/7990/4679/files/capital_cursive_letters_images.pdf
- https://cdn.shopify.com/s/files/1/0268/7270/9313/files/many_lives_many_masters_download.pdf
- https://cdn.shopify.com/s/files/1/0440/8151/2613/files/40529423118.pdf
- https://cdn.shopify.com/s/files/1/0477/2265/9996/files/53267703285.pdf
- https://cdn-cms.f-static.net/uploads/4382779/normal_5f935bc83e575.pdf
- https://cdn-cms.f-static.net/uploads/4382405/normal_5f8e6db56d598.pdf
- https://uploads.strikinglycdn.com/files/97cadfa2-08b1-4cf7-bb86-6df39806f55f/guzoweje.pdf
- https://uploads.strikinglycdn.com/files/61b86239-1fc9-429d-8a09-a3baa12a446f/filos.pdf
- https://uploads.strikinglycdn.com/files/af5f64a5-86a7-4fab-b7d2-8de774e9fcea/47071287444.pdf
- https://uploads.strikinglycdn.com/files/008f02df-437c-4685-ab7c-ad50f988fd82/50606324770.pdf
- https://uploads.strikinglycdn.com/files/702c208d-b9cb-4aba-93a3-c49f244cfeed/roxufabaruwase.pdf
- https://uploads.strikinglycdn.com/files/b8da1f04-370b-4141-85bc-e952e40dfced/raxameduzi.pdf
- https://uploads.strikinglycdn.com/files/09dfe456-dbf4-4aa2-8eb1-2b84daeab3b0/fezewusaduv.pdf
- https://uploads.strikinglycdn.com/files/9442a704-e484-4c93-9ce7-da5806fece69/derecho_administrativo_martinez_morales.pdf
- https://uploads.strikinglycdn.com/files/dfaf2195-ce29-466d-a083-b9adda485658/zapijagiwenaw.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report