SUSPICIOUS — gadelubimiwiziwuzel.pdf
SUSPICIOUS — gadelubimiwiziwuzel.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e95641027bb3ef3682d3fda1047e301b19b8d84625f14889135779ee942f1c5b - SHA-1:
f41f18ec508d7700345f4d3fda359566cfc5db28 - MD5:
46eda650c3c08a622221a342d3435667 - ssdeep:
768:GgGzpDOp5B0nL15KE6SAm6VBTqjA9VCrLZ4xrlih9tZ4zoT4bnLGoHu:TGFKpgJW0R4VlUtOzekLGoHu - TLSH:
T1E8329EF31097ED5CBB8B9B03BDAA106A6086C7896127E76004D8373CD57C1BE7E61861 - Submitted as: gadelubimiwiziwuzel.pdf
- File type: pdf · Size: 43647 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=witcher%203%20swamp%20thing, https://cdn.shopify.com/s/files/1/0437/3744/8609/files/cal_poly_pomona_directory.pdf, https://cdn.shopify.com/s/files/1/0496/7756/6109/files/windows_10_1909_dns_server_not_responding.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=witcher%203%20swamp%20thing
- https://cdn.shopify.com/s/files/1/0437/3744/8609/files/cal_poly_pomona_directory.pdf
- https://cdn.shopify.com/s/files/1/0496/7756/6109/files/windows_10_1909_dns_server_not_responding.pdf
- https://cdn.shopify.com/s/files/1/0434/8670/7876/files/wovekafajixediva.pdf
- https://cdn.shopify.com/s/files/1/0497/9359/7601/files/prophet_isaiah_biography.pdf
- https://cdn.shopify.com/s/files/1/0428/2613/7756/files/conference_presentation_guidelines.pdf
- https://cdn-cms.f-static.net/uploads/4368469/normal_5f8782f1bd08f.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f8706f2c764e.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f87740019a51.pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f8720937f60d.pdf
- https://site-1042777.mozfiles.com/files/1042777/wimudosevabasisovine.pdf
- https://site-1037920.mozfiles.com/files/1037920/mevusijemoguzu.pdf
- https://cdn.shopify.com/s/files/1/0427/6404/2396/files/extra_large_toaster_oven.pdf
- https://cdn.shopify.com/s/files/1/0471/0649/0518/files/19197736659.pdf
- https://cdn.shopify.com/s/files/1/0481/3884/6371/files/creating_a_table_in_redis.pdf
- https://cdn.shopify.com/s/files/1/0481/9756/6616/files/bergusia_forge_drones_location.pdf
- https://cdn.shopify.com/s/files/1/0266/8586/6177/files/another_word_for_capable_of_being_worked_out.pdf
- https://uploads.strikinglycdn.com/files/6a4681c8-af06-4aa3-a8e9-19f3dfd7660c/39611828571.pdf
- https://uploads.strikinglycdn.com/files/e80565e8-3b7e-48bf-beba-81ca07167258/xiwebimidiwebir.pdf
- https://uploads.strikinglycdn.com/files/fe8488d0-88bb-42b0-a027-b117b9dfb3e4/63187684015.pdf
- https://uploads.strikinglycdn.com/files/882ed7a7-80bc-48ea-9d5a-32b6a64be5e2/moberugegomanoma.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1042777.mozfiles.com
- site-1037920.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report