SUSPICIOUS — xefabuwevado_xisekokakoluka.pdf
SUSPICIOUS — xefabuwevado_xisekokakoluka.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
0a6f2a89fc9e4edb3d9d4835e8095344d23de3af2a26d0d7e026496a81202d63 - SHA-1:
37e2c2fde06c610c49a9b84f3c33eeeaa380341c - MD5:
a6a577c6d355eec2d86d746430400410 - ssdeep:
1536:4GFmpb6VqdK5R7KZzOk39D/rnW2pq37zv57g:VFmpcqdK5R+Zzn3N/rW26T50 - TLSH:
T13135AEF310E7ED8D7E87675359B712A4608AC28D6137E3A0848C7B6D98B81BD7F10820 - Submitted as: xefabuwevado_xisekokakoluka.pdf
- File type: pdf · Size: 59604 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hks%20ssqv%20installation%20manual, https://site-1039508.mozfiles.com/files/1039508/guxolelegifu.pdf, https://site-1043175.mozfiles.com/files/1043175/51247477272.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hks%20ssqv%20installation%20manual
- https://site-1039508.mozfiles.com/files/1039508/guxolelegifu.pdf
- https://site-1043175.mozfiles.com/files/1043175/51247477272.pdf
- https://site-1043599.mozfiles.com/files/1043599/jinemegetoziguvomo.pdf
- https://cdn-cms.f-static.net/uploads/4367302/normal_5f8765a11ab70.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f8725d2a0776.pdf
- https://site-1039405.mozfiles.com/files/1039405/danatuxabanapukole.pdf
- https://site-1039563.mozfiles.com/files/1039563/xawof.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f871a1db1a21.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f877322ed7ad.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f8786330f993.pdf
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f8766e972251.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f870ad23ba70.pdf
- https://cdn-cms.f-static.net/uploads/4366358/normal_5f873ca1c4980.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f87254fe71eb.pdf
- https://cdn-cms.f-static.net/uploads/4366652/normal_5f87269ad4f45.pdf
- https://uploads.strikinglycdn.com/files/86d6bfd3-fa36-46c8-904b-41c0b3e69ec9/1744690557.pdf
- https://uploads.strikinglycdn.com/files/84236393-dcaf-4234-91db-0a3054fea9f9/72406498872.pdf
- https://uploads.strikinglycdn.com/files/5045488b-7b8d-4eb9-b146-d6d522dd0b2f/wopajiluw.pdf
- https://uploads.strikinglycdn.com/files/e4429b22-3493-48a7-97d9-19ef2db0e1af/33496595478.pdf
- https://uploads.strikinglycdn.com/files/d2924c94-390d-4ff6-84a3-c2d403947b54/fovekovavitapileraviromor.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- site-1039508.mozfiles.com
- site-1043175.mozfiles.com
- site-1043599.mozfiles.com
- cdn-cms.f-static.net
- site-1039405.mozfiles.com
- site-1039563.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report