SUSPICIOUS — dubalukam.pdf
SUSPICIOUS — dubalukam.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a94842c30db6341c9f14d46c06ef6be8d680b89a4e30ecc49321e386ed86685d - SHA-1:
77c2363b9b45ba8643459c33226d155e0eb579fe - MD5:
8671bae4c93a3b3bb3c4cb7aa9591561 - ssdeep:
768:xgGzpDReeRZGd9j1aTWxit7ERwvIP3R1W6MBxUoyaxWo3YUEjeKVRnd5y8uFl:CGF9esvIP3keopUo37E66ndXuFl - TLSH:
T148328CF35093ED8C3A8B9B03ADBA11AD704AD28D20369790548CB76CD47CAED7E10A51 - Submitted as: dubalukam.pdf
- File type: pdf · Size: 46145 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pals%20pocket%20reference%20card%20free%20down, https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/livudoninabux.pdf, https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/b2ec1e12114.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pals%20pocket%20reference%20card%20free%20down
- https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/livudoninabux.pdf
- https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/b2ec1e12114.pdf
- https://wepeweguwerixum.weebly.com/uploads/1/3/1/8/131856135/4028075.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3532345.pdf
- https://cdn.shopify.com/s/files/1/0429/1995/2550/files/damodatuke.pdf
- https://cdn.shopify.com/s/files/1/0434/6108/3296/files/fallout_4_voice_randomizer.pdf
- https://cdn.shopify.com/s/files/1/0441/2764/9944/files/mavepowunil.pdf
- https://uploads.strikinglycdn.com/files/6e3e3e32-a944-45bb-96aa-cfd53ff8d6df/95357819886.pdf
- https://uploads.strikinglycdn.com/files/52cde90a-9a9f-4333-accb-636f7d7ad864/jijezokotumabolu.pdf
- https://uploads.strikinglycdn.com/files/dda02140-3279-441d-aaeb-cbea964c18ed/33626493640.pdf
- https://uploads.strikinglycdn.com/files/8ab0579a-8aa0-4636-b8ac-6ba0901fbeab/72658468731.pdf
- https://uploads.strikinglycdn.com/files/b2ec71c3-11b5-46e6-a80a-71ff11e4353f/92201050227.pdf
- https://uploads.strikinglycdn.com/files/eb97caa3-53d9-47c8-8916-9c34e7997bcf/11757252827.pdf
- https://uploads.strikinglycdn.com/files/d8d1d524-bed4-4155-b66e-0ff82f544f92/femajilutezitemi.pdf
- https://uploads.strikinglycdn.com/files/5b2675e5-7dae-4cb2-a1f8-9bad6b1e4318/85231940161.pdf
- https://uploads.strikinglycdn.com/files/f08dab25-fcad-455b-92bb-0d0bc00be670/44611154685.pdf
- https://cdn.shopify.com/s/files/1/0268/9341/8681/files/death_lotus_disciple.pdf
- https://cdn.shopify.com/s/files/1/0485/8494/9920/files/lg_g2_weather_widget_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0483/5619/6515/files/netima.pdf
- https://cdn.shopify.com/s/files/1/0480/4850/4991/files/materi_metabolisme_karbohidrat.pdf
- https://cdn.shopify.com/s/files/1/0482/0061/4040/files/hare_and_hound.pdf
- https://cdn-cms.f-static.net/uploads/4371020/normal_5f890eaa781ae.pdf
- https://cdn-cms.f-static.net/uploads/4369343/normal_5f8a89893bbda.pdf
- https://cdn-cms.f-static.net/uploads/4367674/normal_5f874b002d931.pdf
Embedded domains
- cctraff.ru
- wekubuzebebam.weebly.com
- sakuvida.weebly.com
- wepeweguwerixum.weebly.com
- zoxuzuxebexot.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report