SUSPICIOUS — 8569445.pdf
SUSPICIOUS — 8569445.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
72a3b74cda2fc39a9c92e30871ae61ac8e7af43e99b5ebf4b95da03c5c42eef2 - SHA-1:
50911b0f845b99cdad5365b12e3c0ae2494a68e6 - MD5:
3008b83a10dca7c93e60a0806fb1d138 - ssdeep:
3072:tF4p+XXRRxVGtMKtdqNP7Xn8uuKjf/x2uviVStSZ:z6uXRRxsMKjQ7n8iXYuwD - TLSH:
T1683BF1F314DFDD8E99839B076DAE24A91182DA4972B3BB1404C5792CD13C3BC6DA0A71 - Submitted as: 8569445.pdf
- File type: pdf · Size: 111366 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=maytag%20maxima%20washer%20error%20codes%20e01%20f09, https://uploads.strikinglycdn.com/files/563247a0-8b84-437f-9598-976770ce1323/89347890805.pdf, https://uploads.strikinglycdn.com/files/1ff206f0-7db0-4d62-ac5e-3c4f731d0612/zidemezegivonaduzem.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=maytag%20maxima%20washer%20error%20codes%20e01%20f09
- https://uploads.strikinglycdn.com/files/563247a0-8b84-437f-9598-976770ce1323/89347890805.pdf
- https://uploads.strikinglycdn.com/files/1ff206f0-7db0-4d62-ac5e-3c4f731d0612/zidemezegivonaduzem.pdf
- https://uploads.strikinglycdn.com/files/95cbc57c-dc23-469b-aa83-7ea7e2b039aa/lobut.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f874be646a8f.pdf
- https://uploads.strikinglycdn.com/files/8dd46b6a-e522-4349-8531-817b12defd35/mupokefipefixaje.pdf
- https://uploads.strikinglycdn.com/files/1cd050b2-14ea-4743-ae36-b71d78972b4c/susapolejefuxuzadizeje.pdf
- https://cdn-cms.f-static.net/uploads/4366653/normal_5f874aa7a49e8.pdf
- https://cdn-cms.f-static.net/uploads/4368265/normal_5f877131064a5.pdf
- https://site-1037164.mozfiles.com/files/1037164/40023833347.pdf
- https://site-1040360.mozfiles.com/files/1040360/82235665361.pdf
- https://site-1038505.mozfiles.com/files/1038505/47189466584.pdf
- https://site-1038890.mozfiles.com/files/1038890/45501102164.pdf
- https://uploads.strikinglycdn.com/files/83a679fe-26d7-4247-bdfc-125687d88a51/pokixurosig.pdf
- https://uploads.strikinglycdn.com/files/69691ed7-19e2-4cc5-bce8-8d1207b755f6/87035608040.pdf
- https://uploads.strikinglycdn.com/files/080b122d-74cd-4379-b210-66a6c23d5024/simosowelapiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1037164.mozfiles.com
- site-1040360.mozfiles.com
- site-1038505.mozfiles.com
- site-1038890.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report