SUSPICIOUS — wudizop.pdf
SUSPICIOUS — wudizop.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
612bc7f514af2ecc00d4a512a264290ef1a740cd7a83cca78ec390de0b67b810 - SHA-1:
26e96182043200dc3c0880b761ef52f22fdc0767 - MD5:
d3ff34a0d2b665fd0087febebe80357c - ssdeep:
1536:+GFrge4XnSXer9tGxFukf77blOygneiYq0ge5:nFrge/ur9tGikrlOyIei50gQ - TLSH:
T1CD338DF311A3EC8CBB8FAF43A9BB1499504687896136D7605498772CC0BCABD7F01A50 - Submitted as: wudizop.pdf
- File type: pdf · Size: 50503 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=konoha%20wants%20naruto%20back%20fanfiction, https://cdn-cms.f-static.net/uploads/4365659/normal_5f86f47359702.pdf, https://cdn-cms.f-static.net/uploads/4373241/normal_5f88bdf33e324.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=konoha%20wants%20naruto%20back%20fanfiction
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f86f47359702.pdf
- https://cdn-cms.f-static.net/uploads/4373241/normal_5f88bdf33e324.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f87e60f5bc73.pdf
- https://site-1043042.mozfiles.com/files/1043042/58022703335.pdf
- https://site-1042185.mozfiles.com/files/1042185/tiwuwujerukimosi.pdf
- https://site-1048444.mozfiles.com/files/1048444/mivobajegokev.pdf
- https://uploads.strikinglycdn.com/files/6b6d328c-a1a9-4e33-ba24-2b3aa65ba029/kurudivaz.pdf
- https://uploads.strikinglycdn.com/files/3bc5d94d-2bc7-438b-bdb0-131710b8c85e/73236424610.pdf
- https://uploads.strikinglycdn.com/files/70bdf457-5b06-4213-9215-488ff88ffcec/kofiwod.pdf
- https://uploads.strikinglycdn.com/files/650b2b47-5c6b-4972-8057-d98ec12ba20c/xerilavesisetow.pdf
- https://uploads.strikinglycdn.com/files/92b4126b-d763-4e80-9564-0750e1643cb5/gitotikosomeramor.pdf
- https://uploads.strikinglycdn.com/files/bb1c6455-4a70-4d0f-ba3b-3b8ce297f349/10797606530.pdf
- https://uploads.strikinglycdn.com/files/e9c456ee-34c7-47ca-b8b0-fe117f5ea3d7/fekuvaz.pdf
- https://uploads.strikinglycdn.com/files/261e590d-31c9-4f70-81c5-f5437a63ad29/21503058353.pdf
- https://uploads.strikinglycdn.com/files/f376d76b-ee33-4207-8a1b-721cf3618be8/9708088995.pdf
- https://uploads.strikinglycdn.com/files/22340329-ba8f-466c-9fe5-bb745aa1b45e/90059659740.pdf
- https://cdn.shopify.com/s/files/1/0502/2144/9374/files/ingersoll_rand_reciprocating_compressor_manual.pdf
- https://cdn.shopify.com/s/files/1/0497/3903/8874/files/unlisted_watch_battery_replacement.pdf
- https://cdn.shopify.com/s/files/1/0430/8434/9591/files/philips_soup_maker_amazon.pdf
- https://cdn.shopify.com/s/files/1/0437/8748/5342/files/xisowikaz.pdf
- https://cdn.shopify.com/s/files/1/0428/9141/1615/files/my_favorite_groomer_videos.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1043042.mozfiles.com
- site-1042185.mozfiles.com
- site-1048444.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report