SUSPICIOUS — zawozusajabak_xoxovuniguvitiv_galiguru_nizigumujuvamo.pdf
SUSPICIOUS — zawozusajabak_xoxovuniguvitiv_galiguru_nizigumujuvamo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
247962992fe0ed804e2b229ff8cc490430bcafb58d8f6007e941ab1ebc50242d - SHA-1:
03c2b9f70fd0bec553df7f1c2fbcfc0e1189c34e - MD5:
96e3e0ee3074295e1aab2dbbc57c87bd - ssdeep:
768:sgGzpDJpBuY5KuJ4pYROLR1ScNouKXTY9i+yTcRHR8J/jEhKsBKHyNOd:pGF1pFcRlPRe7wOHyNOd - TLSH:
T1AD328DF32053ED4CBBCB9B53ADBB1199654AD38DA4239791089C6B6CC5BC2AD3F40421 - Submitted as: zawozusajabak_xoxovuniguvitiv_galiguru_nizigumujuvamo.pdf
- File type: pdf · Size: 44989 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=lost%20vape%20orion%20dna%20plus%20manual, https://cdn-cms.f-static.net/uploads/4370555/normal_5f8a31a4b1326.pdf, https://cdn-cms.f-static.net/uploads/4380229/normal_5f8ddc4178243.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=lost%20vape%20orion%20dna%20plus%20manual
- https://cdn-cms.f-static.net/uploads/4370555/normal_5f8a31a4b1326.pdf
- https://cdn-cms.f-static.net/uploads/4380229/normal_5f8ddc4178243.pdf
- https://cdn-cms.f-static.net/uploads/4368748/normal_5f8aed52e6a79.pdf
- https://cdn-cms.f-static.net/uploads/4385612/normal_5f94de6912cfe.pdf
- https://donikigegetala.weebly.com/uploads/1/3/4/3/134311768/075476ce391b3a7.pdf
- https://cdn-cms.f-static.net/uploads/4373985/normal_5f8fc4a683fa2.pdf
- https://cdn-cms.f-static.net/uploads/4368245/normal_5f8e5ef3d5630.pdf
- https://cdn-cms.f-static.net/uploads/4369904/normal_5f94229f915f2.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f87ae07a099c.pdf
- https://cdn-cms.f-static.net/uploads/4403260/normal_5f9116543dbea.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/somulimezopomab-nolapuxoduvamak.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/199877.pdf
- https://xavujome.weebly.com/uploads/1/3/0/7/130739328/jumugefevi.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/3703292.pdf
- https://vibebivenef.weebly.com/uploads/1/3/1/4/131412032/roxebixa.pdf
- https://s3.amazonaws.com/fasanag/blueprints_neurology_5th_edition.pdf
- https://s3.amazonaws.com/waxapoz/best_part_daniel_caesar_piano_sheet_music.pdf
- https://s3.amazonaws.com/sojaxub/neguranukesadixajumesit.pdf
- https://s3.amazonaws.com/xanebavifamopez/cetoconazol_pomada_bula.pdf
- https://s3.amazonaws.com/jamokaroxoj/tifuwapopolofejodepedupiv.pdf
- https://s3.amazonaws.com/zifozujiwi/29101447197.pdf
- https://s3.amazonaws.com/sepawi/80349482803.pdf
- https://s3.amazonaws.com/henghuili-files2/rekej.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- donikigegetala.weebly.com
- pigogokeda.weebly.com
- mogilifus.weebly.com
- xavujome.weebly.com
- tipefejiri.weebly.com
- vibebivenef.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report