SUSPICIOUS — wijifawewodum.pdf
SUSPICIOUS — wijifawewodum.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c023bb0154e3fe6dbe5330b4631176d90dfe2c4b78d869fea5849418957ee265 - SHA-1:
8d3ef6b06da3242983fcfcf590e64d0ea07845dc - MD5:
fcd007207ceb8c2ca861c2bba963e14f - ssdeep:
1536:BGFHpDGI7T5EC7Dt1rs2LTWQiKAAmkKld:kFHpqI7lEwp1rBLTWJKPjQ - TLSH:
T10034AEF31097ED4C778B6B07ADEB01A9714AC78EA13297A04848672CD4BC9ED2E11A51 - Submitted as: wijifawewodum.pdf
- File type: pdf · Size: 56199 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pioneer%20car%20stereos%20manuals, https://uploads.strikinglycdn.com/files/4d48355d-75cc-4ae2-989b-6dafbb318f78/zabozimapeludomo.pdf, https://uploads.strikinglycdn.com/files/24aac7f2-e9a0-4b8b-9de6-d53a8f3916c6/vusotetusokigejosimetew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pioneer%20car%20stereos%20manuals
- https://uploads.strikinglycdn.com/files/4d48355d-75cc-4ae2-989b-6dafbb318f78/zabozimapeludomo.pdf
- https://uploads.strikinglycdn.com/files/24aac7f2-e9a0-4b8b-9de6-d53a8f3916c6/vusotetusokigejosimetew.pdf
- https://uploads.strikinglycdn.com/files/35f865d5-cbcf-4e78-a15d-e7a273c75979/zasal.pdf
- https://cdn.shopify.com/s/files/1/0500/4312/5917/files/internet_archive_telugu_books.pdf
- https://cdn.shopify.com/s/files/1/0432/4016/1435/files/january_2013_earth_science_regents_answers.pdf
- https://uploads.strikinglycdn.com/files/5ad56cd1-75a0-489a-aa27-cfca52cc12be/bijusinegas.pdf
- https://uploads.strikinglycdn.com/files/5c2c56d3-02f1-4fdb-9a13-3644db907bb8/2207627430.pdf
- https://uploads.strikinglycdn.com/files/df4ca0f5-d7f5-4d74-a376-13aa8e5fe2be/tujododedowuto.pdf
- https://uploads.strikinglycdn.com/files/9e3bcc14-f042-4761-9194-f644a1f2b90a/94606558943.pdf
- https://uploads.strikinglycdn.com/files/2d58ea77-492c-4c95-aaa4-e05c808ab7e5/14885814131.pdf
- https://site-1037005.mozfiles.com/files/1037005/29262359391.pdf
- https://site-1040175.mozfiles.com/files/1040175/2624013375.pdf
- https://site-1038376.mozfiles.com/files/1038376/towovufalubepeduba.pdf
- https://site-1040670.mozfiles.com/files/1040670/19989984159.pdf
- https://site-1043245.mozfiles.com/files/1043245/sefawi.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f8724087e310.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f870a8922d02.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f8729eed27d6.pdf
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f8738b355525.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f873e3726f25.pdf
- https://site-1042657.mozfiles.com/files/1042657/wukojo.pdf
- https://site-1036783.mozfiles.com/files/1036783/talage.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1037005.mozfiles.com
- site-1040175.mozfiles.com
- site-1038376.mozfiles.com
- site-1040670.mozfiles.com
- site-1043245.mozfiles.com
- cdn-cms.f-static.net
- site-1042657.mozfiles.com
- site-1036783.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report