SUSPICIOUS — surovugoxigez.pdf
SUSPICIOUS — surovugoxigez.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2247b9fd71f4e608e30cb2f01def96ea8c30e5175e68a88c9196d6a54053d2dc - SHA-1:
71a6775610569829e774dde33be2ba262a23b4e4 - MD5:
708392f233bd065de902d0e4edce0bd7 - ssdeep:
768:DgGzpDNpjdIF3LnJDoAmUQWVfcoVjgiQQER1siwr2vRo/agPV+:8GFJpjdwV3QW+o9zQQEDwr2vR9gPV+ - TLSH:
T1B5318CF35097ED4CBA8B6B03BEEA00995589C74D6137A760948C7B6DC4BC6EC7E00821 - Submitted as: surovugoxigez.pdf
- File type: pdf · Size: 41527 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=girlsdoporn%20behind%20the%20scenes, https://site-1042892.mozfiles.com/files/1042892/pokobadodoramezi.pdf, https://site-1039688.mozfiles.com/files/1039688/10713363707.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=girlsdoporn%20behind%20the%20scenes
- https://site-1042892.mozfiles.com/files/1042892/pokobadodoramezi.pdf
- https://site-1039688.mozfiles.com/files/1039688/10713363707.pdf
- https://site-1037237.mozfiles.com/files/1037237/27512563382.pdf
- https://site-1043910.mozfiles.com/files/1043910/90467535975.pdf
- https://cdn-cms.f-static.net/uploads/4367289/normal_5f879f33bab28.pdf
- https://cdn-cms.f-static.net/uploads/4366646/normal_5f87867164cbb.pdf
- https://cdn-cms.f-static.net/uploads/4367916/normal_5f876a365c23b.pdf
- https://site-1043607.mozfiles.com/files/1043607/29366151056.pdf
- https://site-1040048.mozfiles.com/files/1040048/vetodofalevu.pdf
- https://uploads.strikinglycdn.com/files/24ba0c3a-288c-4e1e-b042-df8e43196201/35455469551.pdf
- https://uploads.strikinglycdn.com/files/a5da8cb7-3378-4fe8-9d56-46db3dba76cf/leruwukogibijotokuvafa.pdf
- https://uploads.strikinglycdn.com/files/30fa82aa-dd3f-441f-87e8-e1aa353d9b54/44924751229.pdf
- https://uploads.strikinglycdn.com/files/9610e71f-e19e-4aa9-a42c-ce642fb8ad68/2592422927.pdf
- https://uploads.strikinglycdn.com/files/65faccc0-0a95-430e-b80f-4acee9345bbf/91158940527.pdf
- https://uploads.strikinglycdn.com/files/26ee7193-2c1d-40a0-acdb-b3ce373694de/tunimukonawedupogelinef.pdf
- https://uploads.strikinglycdn.com/files/f6e29634-f900-4031-9f4a-3c773f08308f/dufil.pdf
- https://site-1039840.mozfiles.com/files/1039840/6739707394.pdf
- https://site-1040669.mozfiles.com/files/1040669/75071269820.pdf
- https://site-1037207.mozfiles.com/files/1037207/62267308331.pdf
- https://site-1048222.mozfiles.com/files/1048222/18278045251.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- site-1042892.mozfiles.com
- site-1039688.mozfiles.com
- site-1037237.mozfiles.com
- site-1043910.mozfiles.com
- cdn-cms.f-static.net
- site-1043607.mozfiles.com
- site-1040048.mozfiles.com
- uploads.strikinglycdn.com
- site-1039840.mozfiles.com
- site-1040669.mozfiles.com
- site-1037207.mozfiles.com
- site-1048222.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report