SUSPICIOUS — valiwadelel.pdf
SUSPICIOUS — valiwadelel.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7b1432ab2c12262bd3c689a4abf869b0f0e1a39b4412b87c66bec3664443a098 - SHA-1:
ac544dcf2a2105ebd8a55449c2b1ab0c7956e02e - MD5:
7b630faf8310a79db9efda411afc1fc1 - ssdeep:
768:TgGzpD7MptWXo17n9EHe79Y+7KRUI69RXt3u8jgJNSocPTygEeqeNDgDPZ4qKSSz:sGFvMpIKOcEUI699t/o2mgntNeOqmz - TLSH:
T10032AEF35083EC4C798B9713ADEA14595189C749723BE760148C7B2ED8BC6BD6E20A70 - Submitted as: valiwadelel.pdf
- File type: pdf · Size: 46935 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=free%20labyrinth%20walk%20quilt%20pattern%20pd, https://cdn.shopify.com/s/files/1/0483/6714/1017/files/93987345538.pdf, https://cdn.shopify.com/s/files/1/0436/9720/9498/files/lirexarog.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=free%20labyrinth%20walk%20quilt%20pattern%20pd
- https://cdn.shopify.com/s/files/1/0483/6714/1017/files/93987345538.pdf
- https://cdn.shopify.com/s/files/1/0436/9720/9498/files/lirexarog.pdf
- https://cdn.shopify.com/s/files/1/0477/5647/6572/files/46977265573.pdf
- https://uploads.strikinglycdn.com/files/2b513809-70cb-4dba-94b8-5828c24a9d68/42417858842.pdf
- https://uploads.strikinglycdn.com/files/c864c0ba-c884-46e1-a7ce-b9e38d320f57/65281897243.pdf
- https://uploads.strikinglycdn.com/files/d7ca9de6-39d5-47be-94fe-c34f9875b1d8/76369588187.pdf
- https://uploads.strikinglycdn.com/files/4041f153-bd0a-4f48-9936-59cc8f0c0352/44881431896.pdf
- https://site-1041779.mozfiles.com/files/1041779/xupofosunenafinabujirizex.pdf
- https://site-1039330.mozfiles.com/files/1039330/55684632292.pdf
- https://site-1042270.mozfiles.com/files/1042270/boxewiwejevutiritod.pdf
- https://site-1038970.mozfiles.com/files/1038970/wolufu.pdf
- https://uploads.strikinglycdn.com/files/2738157a-95cb-422b-a68a-8781470c8e41/8979734161.pdf
- https://uploads.strikinglycdn.com/files/066da927-c24b-4120-b267-02636789655f/legeponusetetu.pdf
- https://uploads.strikinglycdn.com/files/fd19ea43-9c3a-4be7-9027-8504396514c4/poruxata.pdf
- https://uploads.strikinglycdn.com/files/8f5f4cdb-669d-4d78-bb3c-8e53c78a4a2b/sevodamezekakeperugi.pdf
- https://uploads.strikinglycdn.com/files/211e6dd0-1018-4965-8bce-9fb3f6b0dac8/16643130697.pdf
- https://cdn.shopify.com/s/files/1/0479/1825/2198/files/96546823774.pdf
- https://cdn.shopify.com/s/files/1/0499/3328/7592/files/dlink_dir-645_firmware_update.pdf
- https://cdn.shopify.com/s/files/1/0497/4854/1594/files/kiwekosijiradatixofudewu.pdf
- https://cdn.shopify.com/s/files/1/0434/7743/4525/files/11865089829.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1041779.mozfiles.com
- site-1039330.mozfiles.com
- site-1042270.mozfiles.com
- site-1038970.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report