SUSPICIOUS — wudibekevof.pdf
SUSPICIOUS — wudibekevof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d213df13b7c3f6bab84ae127c8ab50673a09368303b114e75e7962c2d54ab29a - SHA-1:
4f76d3b7baba2b80d5086532c16be902db2fe108 - MD5:
c7c7abcf78e0b3193edc9369baef8f6f - ssdeep:
768:LgGzpDaSphP0zCRDmnXuLy8ZiGwz12TcP+4NmqX2oFMFreMNqtiH+H8SV:0GF+SpVfaXB8Zg1BVNmkZFoyMNqtiH+1 - TLSH:
T149327CF350ABDD4C7A8B5F139DEA0169518AC34D62239B605588772DD0BC6BCBF10861 - Submitted as: wudibekevof.pdf
- File type: pdf · Size: 43299 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=advanced%20magick%20for%20beginners%20pdf, https://site-1038771.mozfiles.com/files/1038771/latalulasumumexurukotezi.pdf, https://site-1043257.mozfiles.com/files/1043257/6184152595.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=advanced%20magick%20for%20beginners%20pdf
- https://site-1038771.mozfiles.com/files/1038771/latalulasumumexurukotezi.pdf
- https://site-1043257.mozfiles.com/files/1043257/6184152595.pdf
- https://site-1043405.mozfiles.com/files/1043405/vadogexavejoxovaratiwowi.pdf
- https://site-1038788.mozfiles.com/files/1038788/4364668343.pdf
- https://site-1042840.mozfiles.com/files/1042840/11982423681.pdf
- https://uploads.strikinglycdn.com/files/35c6436f-9f3d-4988-948d-19b16ca3d2ef/33218666777.pdf
- https://uploads.strikinglycdn.com/files/78f23c2f-ceaa-4708-b33e-7fa0b0bdbf60/81219382855.pdf
- https://uploads.strikinglycdn.com/files/f95c962e-c292-4081-b5d6-97e25a337ca4/78782935112.pdf
- https://uploads.strikinglycdn.com/files/20a4e7be-30e8-4333-bd3b-ae44825dc1e6/6049347165.pdf
- https://uploads.strikinglycdn.com/files/6124979f-6273-4fd1-b272-2c6748b0b254/17854897326.pdf
- https://site-1040977.mozfiles.com/files/1040977/7061897084.pdf
- https://site-1039833.mozfiles.com/files/1039833/65251386412.pdf
- https://cdn-cms.f-static.net/uploads/4368495/normal_5f8777bb27cac.pdf
- https://cdn-cms.f-static.net/uploads/4373757/normal_5f88c7ad43b7c.pdf
- https://cdn-cms.f-static.net/uploads/4369507/normal_5f880e7b5ff1d.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/946766ec9.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/dozup-tejejuwovil.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/mezevoxinokimuwamibu.pdf
- https://site-1038998.mozfiles.com/files/1038998/81329972921.pdf
- https://site-1036798.mozfiles.com/files/1036798/lipapoxarezopofasok.pdf
- https://site-1036748.mozfiles.com/files/1036748/18250343971.pdf
- https://site-1036811.mozfiles.com/files/1036811/deguzir.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- site-1038771.mozfiles.com
- site-1043257.mozfiles.com
- site-1043405.mozfiles.com
- site-1038788.mozfiles.com
- site-1042840.mozfiles.com
- uploads.strikinglycdn.com
- site-1040977.mozfiles.com
- site-1039833.mozfiles.com
- cdn-cms.f-static.net
- taxajadotediru.weebly.com
- rimesozarabef.weebly.com
- xojerajap.weebly.com
- site-1038998.mozfiles.com
- site-1036798.mozfiles.com
- site-1036748.mozfiles.com
- site-1036811.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report