SUSPICIOUS — binukevuzimuk.pdf
SUSPICIOUS — binukevuzimuk.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f5369a2b073942c15d2ed48acfeafc6742c558cb3a1f51b98f9cde87b08fbe74 - SHA-1:
88217e94b5c3a2db24459937111362988e92df59 - MD5:
f48ef3fa6ab1d02fa8abe0b75978e928 - ssdeep:
768:qgGzpDIpU4YGsbq3uk6j2xlgkfzgSH0pLPgFJOx+M4RcMdrmQgjnk:3GFspURpj2xeSHaLPowwt1gjnk - TLSH:
T1A7306DF710A3ED4C7A8B6B07BEAB115A508AC78D6136A760088C372DD5BC6FD6F10611 - Submitted as: binukevuzimuk.pdf
- File type: pdf · Size: 39001 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=zanzara%20men, https://cdn.shopify.com/s/files/1/0429/8440/7199/files/12198263432.pdf, https://cdn.shopify.com/s/files/1/0500/2625/0389/files/usda_dietary_guidelines_2020.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=zanzara%20men
- https://cdn.shopify.com/s/files/1/0429/8440/7199/files/12198263432.pdf
- https://cdn.shopify.com/s/files/1/0500/2625/0389/files/usda_dietary_guidelines_2020.pdf
- https://cdn.shopify.com/s/files/1/0432/1512/6692/files/wofeweletatevigifirutivan.pdf
- https://cdn.shopify.com/s/files/1/0266/9556/5499/files/pan_pizza_size_papa_johns.pdf
- https://cdn.shopify.com/s/files/1/0431/4061/2262/files/92618456223.pdf
- https://uploads.strikinglycdn.com/files/82a8f1d2-5ad6-4bce-9722-7944c4d7aa4c/kudadalagatuwamekup.pdf
- https://uploads.strikinglycdn.com/files/eb4fd43e-b89f-4ba2-b6dc-41040192cf2f/kixod.pdf
- https://uploads.strikinglycdn.com/files/df7b98d7-61be-4325-bfd8-4d445062e9bd/16922368853.pdf
- https://uploads.strikinglycdn.com/files/9b409c9b-928f-4162-917f-9be6eca12360/sujitixamujikadopizi.pdf
- https://uploads.strikinglycdn.com/files/1b727a7d-a0cc-42f8-bdfa-290280626c82/16044533429.pdf
- https://site-1042514.mozfiles.com/files/1042514/87304531347.pdf
- https://site-1037824.mozfiles.com/files/1037824/wulugifonila.pdf
- https://site-1036816.mozfiles.com/files/1036816/69527867970.pdf
- https://uploads.strikinglycdn.com/files/1cd1f166-f194-4138-bf04-336f97c1664b/dedibubed.pdf
- https://uploads.strikinglycdn.com/files/b6082c5c-c502-413f-8c00-c870880cd5c0/63214412621.pdf
- https://uploads.strikinglycdn.com/files/4769cecf-81a7-4d2b-9ed8-30c0ea04b57b/tinegameb.pdf
- https://uploads.strikinglycdn.com/files/216cfb88-19e8-4d63-bb84-10362c112caa/36492216366.pdf
- https://site-1041173.mozfiles.com/files/1041173/17999475113.pdf
- https://site-1039617.mozfiles.com/files/1039617/kozapelikefepez.pdf
- https://site-1044238.mozfiles.com/files/1044238/11986316776.pdf
- https://cdn-cms.f-static.net/uploads/4367903/normal_5f87673ea6a48.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f873c8d3d51c.pdf
- https://cdn-cms.f-static.net/uploads/4367916/normal_5f876a0b4b776.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f86f44fe2ada.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1042514.mozfiles.com
- site-1037824.mozfiles.com
- site-1036816.mozfiles.com
- site-1041173.mozfiles.com
- site-1039617.mozfiles.com
- site-1044238.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report