SUSPICIOUS — valipuku-pinimaja-votipebap-falevutu.pdf
SUSPICIOUS — valipuku-pinimaja-votipebap-falevutu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
35f0821775a1c6103649501e0af20ca6800df2faa9efc1f4602496cf49acd957 - SHA-1:
70c28469f1af4c2538460ae3cdfc1ab6d5254efc - MD5:
b780989694cce62ddfc6159a122151f7 - ssdeep:
768:ZgGzpDxpVUZSjmdoHiUN5wdkX5OoVFHgHrhzT1svTGM2XrjRcOefhFgERu3KnBya:aGFtpHMoVFEJT9M2refhF7IanBya - TLSH:
T132328EF350A7FC4D764BAF43AD67105AA04ADB8D613296A054CCA73CE57C5BE3E00A11 - Submitted as: valipuku-pinimaja-votipebap-falevutu.pdf
- File type: pdf · Size: 46489 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=uhd%20vs%20hdr, https://cdn.shopify.com/s/files/1/0486/5274/6920/files/funny_red_panda_jokes.pdf, https://cdn.shopify.com/s/files/1/0441/2506/1272/files/99143912301.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=uhd%20vs%20hdr
- https://cdn.shopify.com/s/files/1/0486/5274/6920/files/funny_red_panda_jokes.pdf
- https://cdn.shopify.com/s/files/1/0441/2506/1272/files/99143912301.pdf
- https://cdn.shopify.com/s/files/1/0496/1049/0022/files/57792954085.pdf
- https://cdn.shopify.com/s/files/1/0486/9639/3878/files/geometry_g_rotations_worksheet_1_answers.pdf
- https://cdn.shopify.com/s/files/1/0464/5129/4376/files/2020_honda_cr_v_manual.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f8718cdc80f7.pdf
- https://uploads.strikinglycdn.com/files/e75f6785-ef5c-4848-a60c-ad88237b23eb/xogiliwumom.pdf
- https://uploads.strikinglycdn.com/files/71dfaa90-9b7b-4fed-8088-e75245be72b2/46994955397.pdf
- https://uploads.strikinglycdn.com/files/9ba5dc3e-7577-43e8-823d-4c164fe233cb/pirubitonalo.pdf
- https://uploads.strikinglycdn.com/files/08a3356c-4a8f-4001-8b39-fabfc92e3721/kazigizakoki.pdf
- https://cdn.shopify.com/s/files/1/0462/6445/1221/files/15398830634.pdf
- https://cdn.shopify.com/s/files/1/0433/2044/3045/files/67832468016.pdf
- https://cdn.shopify.com/s/files/1/0429/1097/4111/files/the_outsiders_chapter_2_answers.pdf
- https://cdn.shopify.com/s/files/1/0428/9085/4566/files/comic_book_script_format.pdf
- https://cdn.shopify.com/s/files/1/0480/7501/4301/files/administracion_financiera_oscar_leon_garcia_gratis.pdf
- https://uploads.strikinglycdn.com/files/4db0376d-c601-4ecf-8cc4-d27dc4c38fed/pejitipadetuwemasol.pdf
- https://uploads.strikinglycdn.com/files/c40a9b52-419d-4833-ab02-9e75dacfc8d6/8981406138.pdf
- https://uploads.strikinglycdn.com/files/8598fca6-c4e5-460a-9832-c9c6b9b555c2/1290108148.pdf
- https://suganolorifumu.weebly.com/uploads/1/3/0/8/130814011/8fbb684b2ec.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/junubozuke_vizipofu_jaxiboxovugur.pdf
- https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/b8f4e66e700fa.pdf
- https://jamafijuzu.weebly.com/uploads/1/3/1/4/131437216/bffcf020.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- suganolorifumu.weebly.com
- tipefejiri.weebly.com
- seririgikum.weebly.com
- jamafijuzu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report