SUSPICIOUS — duledixefubo.pdf
SUSPICIOUS — duledixefubo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9d3f5b257b40f31c161cd3974fbe3b4b3a1e7805e2e9f9fed5b13e74d95affee - SHA-1:
a1b3e5f69bfd4053458d5467f520650de97aae5f - MD5:
41af7a421fccb4cb3d17381eb8c11719 - ssdeep:
768:IAgGzpDWppzxlT49ItQTfCc1XZlejBwLOq+3Cy+0aELqyDsBcgkHN+gBYaXNGMwC:YGFqpnl8ite3ing619hqdQoIbc+oSx - TLSH:
T1B3339EF320A3ED8D7A0B6F13BDA710596449E2886132E7A0598C772CD87CAFD7E10951 - Submitted as: duledixefubo.pdf
- File type: pdf · Size: 49416 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=financial%20statement%20analysis%20and%20valuation%204th%20edition, https://cdn.shopify.com/s/files/1/0432/6123/1262/files/52019260677.pdf, https://cdn.shopify.com/s/files/1/0266/7862/4426/files/41928738470.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=financial%20statement%20analysis%20and%20valuation%204th%20edition
- https://cdn.shopify.com/s/files/1/0432/6123/1262/files/52019260677.pdf
- https://cdn.shopify.com/s/files/1/0266/7862/4426/files/41928738470.pdf
- https://cdn.shopify.com/s/files/1/0501/5833/8210/files/tusevakubadet.pdf
- https://cdn.shopify.com/s/files/1/0429/1330/0647/files/portrait_drawing_tips.pdf
- https://cdn.shopify.com/s/files/1/0434/5774/0957/files/92462904052.pdf
- https://cdn.shopify.com/s/files/1/0479/4803/8311/files/pennridge_north_middle_school_elibrary.pdf
- https://cdn.shopify.com/s/files/1/0461/7194/7161/files/no_mans_sky_cant_find_vykeen_dagger.pdf
- https://cdn.shopify.com/s/files/1/0435/5470/1463/files/86987157526.pdf
- https://cdn.shopify.com/s/files/1/0437/0386/1401/files/tuparawisorabivar.pdf
- https://cdn.shopify.com/s/files/1/0479/2916/3932/files/hanes_middle_school_bell_schedule.pdf
- https://cdn.shopify.com/s/files/1/0471/0649/0518/files/pythagorean_identities_worksheet.pdf
- https://uploads.strikinglycdn.com/files/1c0983b6-5807-4c5b-b448-91541f556a6d/64829035025.pdf
- https://uploads.strikinglycdn.com/files/218188e3-100c-4fc5-86a6-6489d4b788b0/51755597386.pdf
- https://uploads.strikinglycdn.com/files/4ad73754-c499-4327-a593-e99205010e09/lasawebeser.pdf
- https://uploads.strikinglycdn.com/files/056f0661-332a-4589-bc01-82038e726afa/8651042842.pdf
- https://cdn-cms.f-static.net/uploads/4374521/normal_5f893ed235d37.pdf
- https://cdn-cms.f-static.net/uploads/4370275/normal_5f896a3b553db.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f872d7fe537a.pdf
- https://cdn-cms.f-static.net/uploads/4369773/normal_5f89527291024.pdf
- https://cdn.shopify.com/s/files/1/0480/2333/9167/files/povimirapegekupivawiwupo.pdf
- https://cdn.shopify.com/s/files/1/0437/2394/8183/files/muzazaxuxiwijuzu.pdf
- https://cdn.shopify.com/s/files/1/0440/2076/0741/files/mezifomujuzifugobubopojof.pdf
- https://cdn.shopify.com/s/files/1/0499/8935/3622/files/5e_paladin_action_economy.pdf
- https://cdn.shopify.com/s/files/1/0463/1062/1341/files/28418183612.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report