SUSPICIOUS — sebakezokiligod.pdf
SUSPICIOUS — sebakezokiligod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
14789901bfa50ae931fef803f340a23c3f432cf249f279962e9316e779b05945 - SHA-1:
3a3acbed2307c41c65f64d1958e9ee2c72cb751a - MD5:
b8d3ef20ed71b676bc34d486ecb3a21a - ssdeep:
768:VgGzpDVpJ7NncZOSXfIMhyn42HvzygbThse2qLLqRCf5fMs0kWe9ea4R:GGFxpgvI1vWghdLLqQT0kWSepR - TLSH:
T1B5327DF340B7DD4C7ACB6F436AEB1199618AC78D617297A054C82A2CC0BCAFD2F00561 - Submitted as: sebakezokiligod.pdf
- File type: pdf · Size: 45505 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=call%20of%20duty%20black%20ops%202%20crack, https://uploads.strikinglycdn.com/files/94fc1050-1ff0-4fc4-afff-d502857bc3d9/naguxoxubibevifujejut.pdf, https://uploads.strikinglycdn.com/files/9f6f01d0-2fc0-4704-a71b-ce360c29a54c/tijor.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=call%20of%20duty%20black%20ops%202%20crack
- https://uploads.strikinglycdn.com/files/94fc1050-1ff0-4fc4-afff-d502857bc3d9/naguxoxubibevifujejut.pdf
- https://uploads.strikinglycdn.com/files/9f6f01d0-2fc0-4704-a71b-ce360c29a54c/tijor.pdf
- https://uploads.strikinglycdn.com/files/9e2dbf2d-4351-4697-b4ba-9d22c424b563/ramozowipaseluweke.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f8726be4216c.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f8710ffa0cf0.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f8778e80f42f.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f872b3522d26.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f8742ede7e28.pdf
- https://site-1041212.mozfiles.com/files/1041212/volcanic_ash_guide_osrs.pdf
- https://site-1042010.mozfiles.com/files/1042010/memopapulomonixe.pdf
- https://site-1038954.mozfiles.com/files/1038954/dikinagulipomudukerebegu.pdf
- https://site-1043248.mozfiles.com/files/1043248/vaxaxomeweruv.pdf
- https://site-1043876.mozfiles.com/files/1043876/dudafobegum.pdf
- https://site-1038532.mozfiles.com/files/1038532/sefananebekipivojezal.pdf
- https://site-1042205.mozfiles.com/files/1042205/16808453251.pdf
- https://cdn-cms.f-static.net/uploads/4369665/normal_5f87db6cb48ce.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f87edddcd801.pdf
- https://cdn-cms.f-static.net/uploads/4366664/normal_5f8748949a345.pdf
- https://site-1042821.mozfiles.com/files/1042821/view_links_in_excel_worksheet.pdf
- https://site-1036816.mozfiles.com/files/1036816/wajeg.pdf
- https://site-1039576.mozfiles.com/files/1039576/64902123392.pdf
- https://site-1039386.mozfiles.com/files/1039386/sixidadumezivoxuzon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1041212.mozfiles.com
- site-1042010.mozfiles.com
- site-1038954.mozfiles.com
- site-1043248.mozfiles.com
- site-1043876.mozfiles.com
- site-1038532.mozfiles.com
- site-1042205.mozfiles.com
- site-1042821.mozfiles.com
- site-1036816.mozfiles.com
- site-1039576.mozfiles.com
- site-1039386.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report