SUSPICIOUS — bovuzikudopizufeferufij.pdf
SUSPICIOUS — bovuzikudopizufeferufij.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
0c28873b1eb829564a8f4c99f940b4ec39eabffa5a806d6dd5d90fd0a19f2801 - SHA-1:
d8c21f75674d1d6a7b75b74ccefc6fd55b4cfe50 - MD5:
72bcaf1e689ac1f8e253d3317e596af8 - ssdeep:
768:MpgGzpD7wo3/nbsXl6/sGhJ910Acnfs7s11TtecfyGoFyL5MM5NtzSWWrOumdY:MKGFPV/wVChTO1pLGW3zSVaumdY - TLSH:
T1E2329DF350B3EE8C7AC6AF03AAEA20595149CB8C2136D76454D8367DC5F82BE7E10911 - Submitted as: bovuzikudopizufeferufij.pdf
- File type: pdf · Size: 45917 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=upsc+calendar+2020+pdf+download, https://cdn.shopify.com/s/files/1/0439/3772/6622/files/absite_review_practice_questions_fiser.pdf, https://cdn.shopify.com/s/files/1/0440/2846/1206/files/fejosewujegedob.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=upsc+calendar+2020+pdf+download
- https://cdn.shopify.com/s/files/1/0439/3772/6622/files/absite_review_practice_questions_fiser.pdf
- https://cdn.shopify.com/s/files/1/0440/2846/1206/files/fejosewujegedob.pdf
- https://cdn.shopify.com/s/files/1/0437/7051/1521/files/acupressure_points_download.pdf
- https://uploads.strikinglycdn.com/files/afff06da-c81c-439b-ad63-d4eb1828d00c/585532401.pdf
- https://uploads.strikinglycdn.com/files/3ac3d08e-e2c7-4c7f-b375-53dd5eea7052/rizifafufetoxoz.pdf
- https://uploads.strikinglycdn.com/files/0cf5f4d4-73ed-42e4-801f-410512688093/xisesojuxupeguzuveres.pdf
- https://uploads.strikinglycdn.com/files/3f619fb5-2e4b-48ee-9e19-9e5bf066b439/30452469113.pdf
- https://uploads.strikinglycdn.com/files/53cd674a-5f24-43b9-aa0e-dad964292e1e/kogumikis.pdf
- https://uploads.strikinglycdn.com/files/bf66c876-62d3-4b1a-9126-1248c0d886f3/risadazi.pdf
- https://uploads.strikinglycdn.com/files/589d6f67-a9bc-4120-b9ee-d9b5e6b6cfbe/zomaverod.pdf
- https://uploads.strikinglycdn.com/files/7de41efe-c55d-45e1-8ed0-e118dba322ec/pipawaxijiparoxilodikame.pdf
- https://uploads.strikinglycdn.com/files/7cf5080a-891f-48b3-8c2f-76fa00e33456/zutugil.pdf
- https://cdn.shopify.com/s/files/1/0432/2584/1819/files/sailor_moon_manga_espaol.pdf
- https://cdn.shopify.com/s/files/1/0435/4814/7867/files/44046744062.pdf
- https://cdn.shopify.com/s/files/1/0434/9883/2037/files/learners_license_questions_and_answers_south_africa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report