SUSPICIOUS — bapuwaxijos.pdf
SUSPICIOUS — bapuwaxijos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
04e8b2bf3ee5fdf9c92506f5ff844060518ec2b28ae237719510bdb38a041b05 - SHA-1:
13ef38d0dae7a4cd5110465799cc3fa96c61ce20 - MD5:
015af34da4fd4c6dc1e09a895777f039 - ssdeep:
768:/gGzpDIpFrM6XFQwMR/kOVbX+L9xmNVWy1mT8y9ymio/LDtI+XbYLrK:IGFUpFWX82c9ymiodBYLrK - TLSH:
T158316DF350ABED8C7B8B5F53AEBA11A96489C38CA137D7A045C83A6DC07C1BD6E10511 - Submitted as: bapuwaxijos.pdf
- File type: pdf · Size: 42102 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=cawson%20oral%20pathology%20pdf, https://jurizimobijagi.weebly.com/uploads/1/3/0/8/130874317/4374342.pdf, https://linezeludamaxen.weebly.com/uploads/1/3/4/3/134340908/pibufurotifab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=cawson%20oral%20pathology%20pdf
- https://s3.amazonaws.com/padadutiseni/vsepr_theory_examples.pdf
- https://s3.amazonaws.com/sugaguxagu/dodejunepapojum.pdf
- https://s3.amazonaws.com/jijumupade/metubosaxibonoput.pdf
- https://s3.amazonaws.com/rovuweraja/achtung_cthulhu_rpg.pdf
- https://s3.amazonaws.com/besafefaf/ejercicios_something_anything_nothing.pdf
- https://jurizimobijagi.weebly.com/uploads/1/3/0/8/130874317/4374342.pdf
- https://linezeludamaxen.weebly.com/uploads/1/3/4/3/134340908/pibufurotifab.pdf
- https://panidulupeju.weebly.com/uploads/1/3/0/9/130969186/loxam.pdf
- https://cdn-cms.f-static.net/uploads/4374207/normal_5f95b2861054e.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f870ee590070.pdf
- https://cdn-cms.f-static.net/uploads/4421051/normal_5f9711c586a74.pdf
- https://cdn-cms.f-static.net/uploads/4375361/normal_5f8e1837cb310.pdf
- https://cdn-cms.f-static.net/uploads/4371783/normal_5f8b03e14d813.pdf
- https://uploads.strikinglycdn.com/files/80a85376-1de0-4d9b-8973-26b9bc30a658/ropezexemadej.pdf
- https://uploads.strikinglycdn.com/files/192c9fdc-d3ff-4865-a0ff-e7d43f5fff8b/zowukesareduxotefitaka.pdf
- https://uploads.strikinglycdn.com/files/17fe7cb4-491d-473e-9794-4c0fa9e91305/ravelipajetuxawegi.pdf
- https://difiraboveju.weebly.com/uploads/1/3/4/5/134508976/nujiduki-rigev-parusenenexavik-tajedotasifuv.pdf
- https://gapefupekud.weebly.com/uploads/1/3/1/8/131871489/42cc8f21.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f8706ee13dd1.pdf
- https://cdn-cms.f-static.net/uploads/4386086/normal_5f92065dc0c05.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f942cb4b11dc.pdf
- https://cdn-cms.f-static.net/uploads/4380229/normal_5f8dd5102a34e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- jurizimobijagi.weebly.com
- linezeludamaxen.weebly.com
- panidulupeju.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- difiraboveju.weebly.com
- gapefupekud.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report