MALICIOUS — nuziwozonugof.pdf
MALICIOUS — nuziwozonugof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e76b65c90d16cf2d776b6c60cff496d6f14516e92f08e549497a5536ffc72192 - SHA-1:
0d78a690b39cc9d7a9619b3188ae5f2171160e98 - MD5:
c19f1866edc7e1c2fc9c347d7979f34c - ssdeep:
768:QgGzpDwpDBm2p4tpGBSWXSmCZ6v05h41+0zwi4XVjgHSu6aWGHUtvk5XswAmYANh:9GFUp9/jPkJw6euvY8hrANbvd - TLSH:
T1B4316AF35097EC8DBA8BAB43AEAB216E1089D38C5136D750419C372DD17C6AEBD10960 - Submitted as: nuziwozonugof.pdf
- File type: pdf · Size: 40072 bytes
- Verdict: malicious (70/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=zelda%20gba%20rom%20ocarina%20time, https://cdn.shopify.com/s/files/1/0502/4595/9845/files/preschool_registration_sanger_ca.pdf, https://cdn.shopify.com/s/files/1/0482/6785/3986/files/riwatarukine.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=zelda%20gba%20rom%20ocarina%20time
- https://cdn.shopify.com/s/files/1/0502/4595/9845/files/preschool_registration_sanger_ca.pdf
- https://cdn.shopify.com/s/files/1/0482/6785/3986/files/riwatarukine.pdf
- https://cdn.shopify.com/s/files/1/0483/9191/3632/files/wenudojujunuzamad.pdf
- https://cdn.shopify.com/s/files/1/0436/3816/1561/files/institute_of_general_semantics.pdf
- https://cdn.shopify.com/s/files/1/0433/4711/6197/files/fadasapinigitidiji.pdf
- https://cdn.shopify.com/s/files/1/0481/5916/2521/files/72453780813.pdf
- https://cdn.shopify.com/s/files/1/0266/9297/6829/files/ap_biology_lab_05_cellular_respiration_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0483/5298/5251/files/monster_legends_apk_unlimited_everything.pdf
- https://cdn.shopify.com/s/files/1/0440/2741/2645/files/micro_twist_braids_in_atlanta_ga.pdf
- https://cdn.shopify.com/s/files/1/0432/1270/1854/files/adobe_audition_cs3_free_download_with_crack.pdf
- https://uploads.strikinglycdn.com/files/b7737eb6-7a07-4e4b-92fe-5c3d913eefe5/musuvekozuvologo.pdf
- https://uploads.strikinglycdn.com/files/271685b2-af1a-4027-918a-970e46f4a640/6423224572.pdf
- https://uploads.strikinglycdn.com/files/5f41acae-82e4-4cc5-942e-fffec0639fef/45259141664.pdf
- https://uploads.strikinglycdn.com/files/465ed9b0-a392-4288-b219-02e97188dcc7/rixoboweveninobek.pdf
- https://uploads.strikinglycdn.com/files/2da249a0-b13a-4c99-94fe-cac5610c716c/84919830126.pdf
- https://uploads.strikinglycdn.com/files/8d99a1cd-210e-4973-b0d6-e86daae78ccc/nunefuruxepo.pdf
- https://uploads.strikinglycdn.com/files/6282861e-5b72-4861-b5b4-ba5338f47834/xomutekika.pdf
- https://uploads.strikinglycdn.com/files/6b0cc443-1901-4f13-9b67-c5edf76ecf1d/72007567614.pdf
- https://mipirizu.weebly.com/uploads/1/3/2/6/132682564/joroxezipabiju-poberakin-zigifaturevoled-vodedokotopidam.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/tolujimifiv.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/2674488.pdf
- https://cdn.shopify.com/s/files/1/0499/8289/8344/files/application_of_adsorption_chromatography.pdf
- https://cdn.shopify.com/s/files/1/0266/8560/4017/files/87219369868.pdf
- https://cdn.shopify.com/s/files/1/0432/1761/7057/files/vukugubuvokafunel.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- mipirizu.weebly.com
- mojivimimujovo.weebly.com
- digonowokeke.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report