SUSPICIOUS — biwuxun.pdf
SUSPICIOUS — biwuxun.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
05e4e90644a45f5d5c4e77418e9193480367220f5c9ea78ef662f8c18e1b065d - SHA-1:
f0899cdadeac7b4a0b5c205f88f1c8d4436c8165 - MD5:
7a8e9f0758fb3c4ed4124670f27e06ef - ssdeep:
768:BgGzpD4e+A7OcSdlYmftuXrnGidzPFNRvxWEY5hrfR+1UKks0l7kXroeLWdksN:yGFMebFKMtN5FefR+1Z0lABLGksN - TLSH:
T117328EF350DBED8C3ACA9B03ACB7219A154EC7486036AB50594C6B6CD4BC6BD7F10920 - Submitted as: biwuxun.pdf
- File type: pdf · Size: 46716 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=optical%20fiber%20communication, https://uploads.strikinglycdn.com/files/d4a23d74-d672-49c6-a481-1976c786fe8b/17709243729.pdf, https://uploads.strikinglycdn.com/files/dfe0e0a5-db1c-4224-bb48-75f2bea1addb/zawaligatumifelop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=optical%20fiber%20communication
- https://uploads.strikinglycdn.com/files/d4a23d74-d672-49c6-a481-1976c786fe8b/17709243729.pdf
- https://uploads.strikinglycdn.com/files/dfe0e0a5-db1c-4224-bb48-75f2bea1addb/zawaligatumifelop.pdf
- https://uploads.strikinglycdn.com/files/7229ad62-da1a-46cf-bba4-db79c2ecf929/bonapanetelexi.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/32e063a95e.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/8746e.pdf
- https://melegejisud.weebly.com/uploads/1/3/1/3/131379421/5091743.pdf
- https://meboguvogo.weebly.com/uploads/1/3/1/4/131437667/lixedofegom.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/xixaparunixigoz_fokasisatetiful_lujeloralugomuf_jipowovogoz.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/ce02014a20d.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/setopovasewar-xijoj.pdf
- https://senobatupubem.weebly.com/uploads/1/3/1/4/131437889/c350b5a07dd4a3.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/gavirevudelisi_mowonemodu_xasux.pdf
- https://varipejat.weebly.com/uploads/1/3/0/7/130739080/dfb1fe63.pdf
- https://vaxajiwozoli.weebly.com/uploads/1/3/1/6/131637631/wiwiduwakuxu.pdf
- https://gapefupekud.weebly.com/uploads/1/3/1/8/131871489/ruzupaxawija.pdf
- https://wegupufula.weebly.com/uploads/1/3/0/8/130813429/kosusubevogiban.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/613a711ec7ef.pdf
- https://degujipimisa.weebly.com/uploads/1/3/1/4/131453395/zopeka.pdf
- https://junoxavod.weebly.com/uploads/1/3/1/3/131384771/rigajeviwor_megasunip_pezojopip.pdf
- https://jovikuveditowe.weebly.com/uploads/1/3/0/8/130874612/7359067.pdf
- https://nubojubixuxo.weebly.com/uploads/1/3/1/4/131410311/1258475.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/e276efd25922.pdf
- https://cdn.shopify.com/s/files/1/0481/6024/3879/files/rolesville_high_school_phone_number.pdf
- https://cdn.shopify.com/s/files/1/0431/9100/9442/files/66219380825.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- keniwuki.weebly.com
- wepugimi.weebly.com
- melegejisud.weebly.com
- meboguvogo.weebly.com
- vilukenuxe.weebly.com
- bedizegoresupa.weebly.com
- dirigesibujov.weebly.com
- senobatupubem.weebly.com
- wetuxabo.weebly.com
- varipejat.weebly.com
- vaxajiwozoli.weebly.com
- gapefupekud.weebly.com
- wegupufula.weebly.com
- fijojonibiw.weebly.com
- degujipimisa.weebly.com
- junoxavod.weebly.com
- jovikuveditowe.weebly.com
- nubojubixuxo.weebly.com
- lipowuripipu.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report