SUSPICIOUS — suvex-xebubonozov-gavubukegago.pdf
SUSPICIOUS — suvex-xebubonozov-gavubukegago.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1d314620fefd7fe95066409faa2f3e6b3441f8e8115f5766d039cd5e09a902e7 - SHA-1:
8b7088f3276f604aab92f335ffd409135bd13da1 - MD5:
78919df864a417ab71d815bb7a48c84a - ssdeep:
768:wgGzpDIpAnklV8MUFgJpsM/QKymKPjCDakZtoolHlmIBjUFT3llnWoPKhb+:dGFUphcCDD9lHlmIBg11lPKhb+ - TLSH:
T12B328DF35093FD4C768B9B038EE71099608AE78DA127A7A1048C6B2CD57C6FD6F11A50 - Submitted as: suvex-xebubonozov-gavubukegago.pdf
- File type: pdf · Size: 43589 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=osrs%20rune%20pure%20quest%20guide, https://cdn-cms.f-static.net/uploads/4365998/normal_5f8716e7a050e.pdf, https://cdn-cms.f-static.net/uploads/4365607/normal_5f8703141a89b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=osrs%20rune%20pure%20quest%20guide
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8716e7a050e.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f8703141a89b.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f8710c78be75.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f86fc71db801.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f870bc5880b8.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8715f1adc84.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f8714e381a19.pdf
- https://site-1036840.mozfiles.com/files/1036840/wujesebowureza.pdf
- https://site-1042658.mozfiles.com/files/1042658/rimavetukijejepubewasub.pdf
- https://site-1041851.mozfiles.com/files/1041851/9383119139.pdf
- https://site-1039496.mozfiles.com/files/1039496/15936551202.pdf
- https://site-1048528.mozfiles.com/files/1048528/39633785565.pdf
- https://uploads.strikinglycdn.com/files/3bfc86cd-2ac8-4cb2-8231-3ff3aeaf161e/97476537665.pdf
- https://uploads.strikinglycdn.com/files/aa7504b8-c058-42d9-a29d-1281e6917bb0/zizasiwerasusuke.pdf
- https://uploads.strikinglycdn.com/files/61bf6f15-b5c0-4b20-9e83-5f4b77ff8550/90631974071.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f86fc54cb3ec.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f870563ba6e9.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f8712c97956c.pdf
- https://cdn.shopify.com/s/files/1/0266/9681/0670/files/12865522193.pdf
- https://cdn.shopify.com/s/files/1/0268/8093/4087/files/keira_knightley_porn.pdf
- https://cdn.shopify.com/s/files/1/0430/0043/0746/files/german_navy_ww2_flag.pdf
- https://cdn.shopify.com/s/files/1/0429/6930/1151/files/norton_anthology_of_american_literature_shorter_9th_edition_ebook.pdf
- https://cdn.shopify.com/s/files/1/0492/2995/5238/files/lijesofefefu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1036840.mozfiles.com
- site-1042658.mozfiles.com
- site-1041851.mozfiles.com
- site-1039496.mozfiles.com
- site-1048528.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report