SUSPICIOUS — 6808592.pdf
SUSPICIOUS — 6808592.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1e93b6bf83df2f32966347ffcf003f7dc0f160a3037be8c2725e09f04671a65a - SHA-1:
51b793bdfd3a38af6b421967aabd8a63ed0af259 - MD5:
bc5e4f4b68678b39a192091bb2af07ae - ssdeep:
768:ngGzpDCpuoJ46dWe7LjuwVwbMoNDut3YsjolUXUbPK3ANPm2fYh:gGFGpzVwbMoNyVHeUXUbySm2fYh - TLSH:
T11A318DF35497ED4CB9866B93ADE71169A4CAC38C6237E72041CC762EC47C6AD6F10860 - Submitted as: 6808592.pdf
- File type: pdf · Size: 41755 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=vermeer%201250%20wood%20chipper%20manual, https://cdn-cms.f-static.net/uploads/4366047/normal_5f871d78a601d.pdf, https://cdn-cms.f-static.net/uploads/4366340/normal_5f870edebfa55.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=vermeer%201250%20wood%20chipper%20manual
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f871d78a601d.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f870edebfa55.pdf
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f870bd085db1.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f87143106e87.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f8711d16e9ef.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f85a58c0e.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f870138bf6fe.pdf
- https://site-1038908.mozfiles.com/files/1038908/6368839499.pdf
- https://site-1042556.mozfiles.com/files/1042556/2641551393.pdf
- https://site-1043694.mozfiles.com/files/1043694/46464422499.pdf
- https://site-1040504.mozfiles.com/files/1040504/77452221307.pdf
- https://site-1037840.mozfiles.com/files/1037840/34034921668.pdf
- https://uploads.strikinglycdn.com/files/1632ef0d-d869-4473-b2ff-c0b44b5bce87/nejugonibadukepomoveteram.pdf
- https://uploads.strikinglycdn.com/files/8e8f64f5-964c-4de4-833a-1d022f8778ac/xesigogarimadelexiso.pdf
- https://uploads.strikinglycdn.com/files/205b4105-5f26-406e-abbe-ae5849db02c4/baxun.pdf
- https://uploads.strikinglycdn.com/files/c0cb3e4f-2d1f-42bb-970c-75d11e4dd05a/fiwaxifebuzuzo.pdf
- https://uploads.strikinglycdn.com/files/90a687cc-36bb-4440-9dca-bad50ba6aa41/3898761729.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f870352bc8cd.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f8719e879df6.pdf
- https://uploads.strikinglycdn.com/files/47bf200e-c4b2-4c05-8952-414e77a20a56/87716204175.pdf
- https://uploads.strikinglycdn.com/files/64892c3f-d783-40b8-80b2-5ff1595fe035/51789179080.pdf
- https://uploads.strikinglycdn.com/files/83db9fd2-2409-4126-bc06-829aa1030b83/715410866.pdf
- https://uploads.strikinglycdn.com/files/6d474cd3-7db2-40d1-87c4-d513a6ff2364/17033438123.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1038908.mozfiles.com
- site-1042556.mozfiles.com
- site-1043694.mozfiles.com
- site-1040504.mozfiles.com
- site-1037840.mozfiles.com
- uploads.strikinglycdn.com
- purplewave.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report