SUSPICIOUS — vitufudomaloxubuf.pdf
SUSPICIOUS — vitufudomaloxubuf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
65cd5ceaa26b87133793a96a657c14bd780bf2dc9d419721e2f7385ac8b2c7d3 - SHA-1:
20f074b4e9a8c3c64a4486997f037051989262e7 - MD5:
f8ff47213e04b82ba558abd9fc8fb8c8 - ssdeep:
768:zgGzpDdpLWeJyMbvYdcKx1Iw+vltCVnEO/3Dz4Sv/1JEo:MGFZpLScYbEtCVnVD0k/1JEo - TLSH:
T1DD317EF310A7ED8CAB8B9F036CBB1099558AD34C7137A3A015D8672DC4BC5AD7E40860 - Submitted as: vitufudomaloxubuf.pdf
- File type: pdf · Size: 41320 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=rf%20&%20ems%20beauty%20instrument%20manual%20pdf, https://cdn-cms.f-static.net/uploads/4419002/normal_5f9605f1f0c94.pdf, https://cdn-cms.f-static.net/uploads/4411479/normal_5f9513ed97818.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=rf%20&%20ems%20beauty%20instrument%20manual%20pdf
- https://s3.amazonaws.com/zunaduxa/70632297436.pdf
- https://s3.amazonaws.com/kopisigapub/bengkulu_selatan_dalam_angka_2017.pdf
- https://s3.amazonaws.com/zijivevip/8919282344.pdf
- https://cdn-cms.f-static.net/uploads/4419002/normal_5f9605f1f0c94.pdf
- https://cdn-cms.f-static.net/uploads/4411479/normal_5f9513ed97818.pdf
- https://s3.amazonaws.com/wotodedaruzuk/tutumafom.pdf
- https://s3.amazonaws.com/senodiw/cv_biodata_format_download.pdf
- https://s3.amazonaws.com/zazelujeju/ice_rajkot_bin_sachivalay_model_paper_2019.pdf
- https://s3.amazonaws.com/xanebavifamopez/calculus_chapter_3.pdf
- https://s3.amazonaws.com/nokiva/first_angle_projection_and_third_angle_projection_difference.pdf
- https://s3.amazonaws.com/domegagowevag/the_hindu_nationalist_movement_in_india.pdf
- https://s3.amazonaws.com/kavitokolezub/mugutami.pdf
- https://s3.amazonaws.com/gixawetopoli/kazuresosorezotovileni.pdf
- https://s3.amazonaws.com/wiwuxot/93736887487.pdf
- https://s3.amazonaws.com/temujonuwu/35277929625.pdf
- https://s3.amazonaws.com/muxozuvalubi/48917256688.pdf
- https://s3.amazonaws.com/rujabepifar/tudugofoxatudabiparelu.pdf
- https://s3.amazonaws.com/liguwubore/54385602638.pdf
- https://uploads.strikinglycdn.com/files/652b9dfa-bbca-4196-ae48-6913b6c11275/vovoxozamedifiwexataxi.pdf
- https://uploads.strikinglycdn.com/files/e63f1dc0-b71e-42f6-8439-82e3ccb9a120/pevolusixuxu.pdf
- https://uploads.strikinglycdn.com/files/f46f724e-3ca4-46d3-9a8f-3010b2349348/38222240349.pdf
- https://uploads.strikinglycdn.com/files/dc3ee80c-0277-4ac0-ba06-0d077aa25171/bokon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report