SUSPICIOUS — duloli.pdf
SUSPICIOUS — duloli.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7a9c6c176320c303b4b28f29353bfcb912b8b1bb37036e2a985c30994e2b4238 - SHA-1:
2783f602bc800cd0e1ff116d1b3bcd494b7759cf - MD5:
ea169b278179d5d706a69a9f38138ba5 - ssdeep:
1536:xGF/pF1uRKbHidUvs696jZ6YK4MTHZnlBQ/t:UF/pFQKTidgo6YK4MzZn6 - TLSH:
T1B833AEF7109BDC4CBA8B5F479AFA105A5186C74C2126E7A045CC7B2CC57CAFDAE20960 - Submitted as: duloli.pdf
- File type: pdf · Size: 52102 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ffxiv%20doman%20reconstruction%20guide, https://uploads.strikinglycdn.com/files/762c04c5-58dc-464b-8201-e0b63cce767d/69111532174.pdf, https://uploads.strikinglycdn.com/files/79de0677-d9c5-4edc-bf97-e0a5a96da99f/13550380438.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ffxiv%20doman%20reconstruction%20guide
- https://uploads.strikinglycdn.com/files/762c04c5-58dc-464b-8201-e0b63cce767d/69111532174.pdf
- https://uploads.strikinglycdn.com/files/79de0677-d9c5-4edc-bf97-e0a5a96da99f/13550380438.pdf
- https://uploads.strikinglycdn.com/files/3c60a8de-38f7-4e0a-a5ab-329fd20b88c9/12614551227.pdf
- https://cdn-cms.f-static.net/uploads/4367648/normal_5f8830e96ec0e.pdf
- https://cdn-cms.f-static.net/uploads/4370059/normal_5f88b83665fa4.pdf
- https://cdn.shopify.com/s/files/1/0500/4358/4662/files/looking_for_alaska_quotes_death.pdf
- https://cdn.shopify.com/s/files/1/0434/3840/7832/files/kunemutadixobugekovefe.pdf
- https://cdn.shopify.com/s/files/1/0433/0648/3876/files/23800262249.pdf
- https://cdn.shopify.com/s/files/1/0495/4646/1336/files/mewimoladexepu.pdf
- https://uploads.strikinglycdn.com/files/98624999-6128-41fe-ba0b-6c74590d08e9/fesaxe.pdf
- https://uploads.strikinglycdn.com/files/55c913bd-953e-42fc-a9fb-c18555e1573d/anime_porn_name.pdf
- https://cdn.shopify.com/s/files/1/0435/3071/5288/files/xisomarebu.pdf
- https://cdn.shopify.com/s/files/1/0438/7271/4920/files/canara_bank_net_banking_fund_transfer.pdf
- https://cdn.shopify.com/s/files/1/0485/0250/5627/files/42668260547.pdf
- https://cdn.shopify.com/s/files/1/0430/7812/3680/files/equations_of_parallel_lines_worksheet_answers.pdf
- https://uploads.strikinglycdn.com/files/4bb4b93d-20bc-4fcb-b2e2-23354b05c31a/61686384776.pdf
- https://uploads.strikinglycdn.com/files/8be04dc0-79f2-44b3-82e9-9b97a6bb8320/jijolajugixibesirawepid.pdf
- https://uploads.strikinglycdn.com/files/a6f6dfac-a6dc-49d5-a101-ea0c6e41c3a4/xetixituvetivadopibuxe.pdf
- https://uploads.strikinglycdn.com/files/b85a48b1-7b59-45e7-bd53-85c31794b430/59844740021.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report