SUSPICIOUS — pitowuwata.pdf
SUSPICIOUS — pitowuwata.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
88d1a2c9355c61cf721a2cec4999286eeec6003a656ba847ca4d0ad6dab12045 - SHA-1:
6333fbcca208a7d8fd4f333d3cffd2e995d2a598 - MD5:
bdad502deba3108a44876e2d283d4d28 - ssdeep:
768:cgGzpDdpwwDY9b81nmQy6CNj4ZNmOpT8KCrVuy91NI8C2GWpqjc6/9tCVJovR:5GFRphpT5C582Bk/VMVJovR - TLSH:
T166329EF354A7DC8C7A8AAB03ADB7215950CECB8C6137DB60898C266CD47C5BD7E00860 - Submitted as: pitowuwata.pdf
- File type: pdf · Size: 45100 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=samsung%20dishwasher%20dmt400rhs%20trouble, https://cdn.shopify.com/s/files/1/0476/8936/7718/files/sundance_spa_repair_manual.pdf, https://cdn.shopify.com/s/files/1/0432/5870/8118/files/29240542159.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=samsung%20dishwasher%20dmt400rhs%20trouble
- https://cdn.shopify.com/s/files/1/0476/8936/7718/files/sundance_spa_repair_manual.pdf
- https://cdn.shopify.com/s/files/1/0432/5870/8118/files/29240542159.pdf
- https://cdn.shopify.com/s/files/1/0485/2416/5282/files/reteaching_activity_the_constitution_answers.pdf
- https://cdn.shopify.com/s/files/1/0479/5131/5111/files/31070343995.pdf
- https://cdn.shopify.com/s/files/1/0431/9015/7474/files/area_code_469_texas.pdf
- https://uploads.strikinglycdn.com/files/cddabc9f-176f-4f0d-8d33-7b192130561e/68865180655.pdf
- https://uploads.strikinglycdn.com/files/ce43430a-4f2b-4aba-9819-78160ec39d13/45550635493.pdf
- https://uploads.strikinglycdn.com/files/6d366a22-7053-453b-ae88-4e5cc59d1d6b/rejonakekogalafidesedare.pdf
- https://cdn.shopify.com/s/files/1/0484/0390/6717/files/99240435272.pdf
- https://cdn.shopify.com/s/files/1/0504/1497/7198/files/87715100576.pdf
- https://cdn.shopify.com/s/files/1/0481/4661/2373/files/hank_williams_lost_highway_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0497/4693/5972/files/how_many_calories_in_a_ribeye_steak_oz.pdf
- https://cdn.shopify.com/s/files/1/0433/6372/9557/files/maplelegends_quest_guide.pdf
- https://uploads.strikinglycdn.com/files/e7b6ef28-c60b-45d4-8d1e-84302db48690/ledokuxokugoromufewo.pdf
- https://uploads.strikinglycdn.com/files/e935f6dd-3981-4645-834b-30f032bacb21/21749391436.pdf
- https://uploads.strikinglycdn.com/files/43eff323-5504-46a9-b83a-6eccfe17df23/52615320207.pdf
- https://uploads.strikinglycdn.com/files/4260cb3c-3a32-497f-9ba9-4423275a2664/86624352008.pdf
- https://uploads.strikinglycdn.com/files/0c349a31-635d-40da-8d5e-c7aa21b637f8/57902229307.pdf
- https://uploads.strikinglycdn.com/files/eae1c6b3-f4ff-42ea-a194-e34dee3fd051/84048495430.pdf
- https://uploads.strikinglycdn.com/files/9435fd24-cefc-4afe-8bfc-5f892f4cac30/71048300236.pdf
- https://uploads.strikinglycdn.com/files/bc608fb5-7b07-4b71-8e4b-f2c2103e9b21/89650044715.pdf
- https://site-1039424.mozfiles.com/files/1039424/82405392478.pdf
- https://site-1043195.mozfiles.com/files/1043195/libabupijovefaxigif.pdf
- https://site-1036910.mozfiles.com/files/1036910/pibuzotedot.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039424.mozfiles.com
- site-1043195.mozfiles.com
- site-1036910.mozfiles.com
- site-1042347.mozfiles.com
- site-1041949.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report