SUSPICIOUS — nedovi-nidobufina.pdf
SUSPICIOUS — nedovi-nidobufina.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4092e9ad323b1954d03e5280c8d920fb9bb2c44df5718497798b53a3b3248e39 - SHA-1:
96039fd961331c44eb7d1f1fcd7e358ed632e4ed - MD5:
10de02800f59a7e78ad95330add32ba9 - ssdeep:
1536:WGFeps40Uta4zFjnk23JZo+FEPYNKS0N5hOgd5YuFeH6i:vFepsutaAnkC5aYESoegd9en - TLSH:
T1D937CFF72057FD8C798B6F03AEA71199A18A8248B0338BD0148C7B2DC4FC6EE5E11955 - Submitted as: nedovi-nidobufina.pdf
- File type: pdf · Size: 69935 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=warframe%20how%20to%20change%20dojo%20spawn, https://uploads.strikinglycdn.com/files/06502603-99ac-4708-8c74-53e90dd51c4b/19514909354.pdf, https://uploads.strikinglycdn.com/files/cb9a8ec7-ad51-42cb-bc4e-b499da96332f/phtls_8_edicion_online.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=warframe%20how%20to%20change%20dojo%20spawn
- https://uploads.strikinglycdn.com/files/06502603-99ac-4708-8c74-53e90dd51c4b/19514909354.pdf
- https://uploads.strikinglycdn.com/files/cb9a8ec7-ad51-42cb-bc4e-b499da96332f/phtls_8_edicion_online.pdf
- https://uploads.strikinglycdn.com/files/5ffefb32-eec7-4238-a0a7-1d7526cb7da9/57769255268.pdf
- https://uploads.strikinglycdn.com/files/1f8645be-a624-4150-9917-ac1115578021/69364488806.pdf
- https://cdn-cms.f-static.net/uploads/4368500/normal_5f8b21bea3a61.pdf
- https://cdn-cms.f-static.net/uploads/4367911/normal_5f8c463cd141a.pdf
- https://cdn-cms.f-static.net/uploads/4369935/normal_5f8964622acdd.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f8750ae19d1a.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f89c05a09c74.pdf
- https://cdn-cms.f-static.net/uploads/4377391/normal_5f89cb28354c4.pdf
- https://cdn-cms.f-static.net/uploads/4370989/normal_5f8bc9cb45dd3.pdf
- https://cdn-cms.f-static.net/uploads/4372673/normal_5f89dc5f9a946.pdf
- https://cdn-cms.f-static.net/uploads/4369318/normal_5f899b3314275.pdf
- https://dudikojegak.weebly.com/uploads/1/3/1/4/131406444/rojunev.pdf
- https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/5007940.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/zebapesuluboxaj.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/5650151.pdf
- https://uploads.strikinglycdn.com/files/ca35b726-8644-4fc8-8b61-1433e73eed15/wikazezev.pdf
- https://uploads.strikinglycdn.com/files/7dada3a7-cf8e-4831-a0c2-520f472ce035/18600415362.pdf
- https://uploads.strikinglycdn.com/files/babcd073-498d-4d38-bc8a-63aa6690b35f/40147696403.pdf
- https://uploads.strikinglycdn.com/files/410512e3-6010-4260-bc21-95066e470164/lozefuzonediri.pdf
- https://uploads.strikinglycdn.com/files/bcd7fec8-c13c-40a4-8633-a347a88cd862/lugozajizixarurinifig.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- dudikojegak.weebly.com
- mogezisatizate.weebly.com
- xojerajap.weebly.com
- dutitujazekap.weebly.com
- jatorogerujew.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report