SUSPICIOUS — gizitixumuf.pdf
SUSPICIOUS — gizitixumuf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c5ddb798f53b57ccde845c5ced4b99151263a83a3ac5df5351e9514f1c3a7f00 - SHA-1:
e28bcda2201bb013a27ccca5e69a3bbb84390f64 - MD5:
362a2ead9119b2e464baa98621c7d155 - ssdeep:
768:gigGzpDHpouQbyHvMxPyw/Lbd6BrQtyA3v1puqnRT9Tw6uzY286+2REPT6Iqryr6:g/GFTpouzBrIK1VBpEPzqemm2 - TLSH:
T1D1327DF340A7FD4D7A8FAB136DAB155E618AC68D713396601588772CD0BCAED3E00A11 - Submitted as: gizitixumuf.pdf
- File type: pdf · Size: 43716 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=vba%20excel%202010%20programacion%20en%20excel%20macros%20y%20lenguaje%20vba%20pdf, https://cdn-cms.f-static.net/uploads/4366662/normal_5f874fe6d094c.pdf, https://cdn-cms.f-static.net/uploads/4366652/normal_5f87b1770fe54.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=vba%20excel%202010%20programacion%20en%20excel%20macros%20y%20lenguaje%20vba%20pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f874fe6d094c.pdf
- https://cdn-cms.f-static.net/uploads/4366652/normal_5f87b1770fe54.pdf
- https://cdn-cms.f-static.net/uploads/4375342/normal_5f89e139eaaf8.pdf
- https://cdn-cms.f-static.net/uploads/4370054/normal_5f88471ab0a44.pdf
- https://cdn-cms.f-static.net/uploads/4367296/normal_5f8a511034c5d.pdf
- https://cdn.shopify.com/s/files/1/0501/5443/8846/files/dikisijexoxowox.pdf
- https://cdn.shopify.com/s/files/1/0439/2324/3176/files/tim_cannon_md.pdf
- https://cdn.shopify.com/s/files/1/0433/2044/3045/files/lillebaby_carrier_complete_instructions.pdf
- https://cdn.shopify.com/s/files/1/0481/8432/8344/files/rudisawafaxexuxosiw.pdf
- https://cdn.shopify.com/s/files/1/0434/7471/4784/files/kuwewupus.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/4078745.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/vilemokoguropebiw.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/demaxevijinubalulu.pdf
- https://cdn.shopify.com/s/files/1/0484/7612/7394/files/72590149964.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/prepositions_of_place_test_with_pictures.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/kandungan_bayam_merah.pdf
- https://cdn.shopify.com/s/files/1/0484/9939/2674/files/crash_fever_tw_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0493/2386/8319/files/39091156640.pdf
- https://cdn.shopify.com/s/files/1/0433/2044/3045/files/skype_apk_download_for_laptop.pdf
- https://cdn.shopify.com/s/files/1/0436/2479/2224/files/ordenes_de_magnitud_fisica.pdf
- https://uploads.strikinglycdn.com/files/d16adf36-fec4-4f4c-8949-e0bde14e8993/pafemeworazav.pdf
- https://uploads.strikinglycdn.com/files/41c42488-690d-427e-a6bc-e86427dbbb1c/43380086817.pdf
- https://uploads.strikinglycdn.com/files/598832ce-cb1f-4238-aae6-5eb0d6c85468/doxidaxasamu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- dirigesibujov.weebly.com
- vimiwegom.weebly.com
- pevugubak.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report