SUSPICIOUS — dulefipalep_jobowajoxugo_wiribulelom_nuzigo.pdf
SUSPICIOUS — dulefipalep_jobowajoxugo_wiribulelom_nuzigo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 49 detection engines flagged it.
Identification
- SHA-256:
25014a1c17620ed20e44dce6f52bc488714573a3fcb9f1203ca5a852fb32afc3 - SHA-1:
d4778d56b16cb2f90c53ddc46efe721e69336a2c - MD5:
5e5819a56b5d58656244358ff5807bcc - ssdeep:
768:VgGzpDCplnRhgcpZl7Y2uspwOhXZ2PmI8X7CayfA5THJV5BEXM6SL:GGFOplR+WZDIDayfA5TpVLh6SL - TLSH:
T1FA337CF75097EE4C7A87AB836EEA11689049C74D6122DBA085DC676CC07C7BD7F00A24 - Submitted as: dulefipalep_jobowajoxugo_wiribulelom_nuzigo.pdf
- File type: pdf · Size: 48897 bytes
- Verdict: suspicious (44/100)
Detections (2 of 49 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=affiliate%20marketing%20pdf%20free, https://uploads.strikinglycdn.com/files/0e134e68-b36d-4af3-91f0-6de7ba091bb5/nanizuginaparoxon.pdf, https://uploads.strikinglycdn.com/files/a2b5c825-4806-43a0-994d-4a2d75354aae/jigukebetolipawodipu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=affiliate%20marketing%20pdf%20free
- https://uploads.strikinglycdn.com/files/0e134e68-b36d-4af3-91f0-6de7ba091bb5/nanizuginaparoxon.pdf
- https://uploads.strikinglycdn.com/files/a2b5c825-4806-43a0-994d-4a2d75354aae/jigukebetolipawodipu.pdf
- https://uploads.strikinglycdn.com/files/3a7e341b-04f7-4d07-b268-9bd0d2a0523b/73146689847.pdf
- https://site-1041587.mozfiles.com/files/1041587/jumuwelejuf.pdf
- https://site-1037215.mozfiles.com/files/1037215/19200710633.pdf
- https://site-1038973.mozfiles.com/files/1038973/88961989682.pdf
- https://site-1036874.mozfiles.com/files/1036874/85671579292.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f86f91d1d457.pdf
- https://cdn-cms.f-static.net/uploads/4366024/normal_5f870f18a5051.pdf
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f8713e402f7d.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f86f614703f2.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f8722a2e6b92.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f872225bf76b.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/8448799.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/vopisovaz.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/ririxuxikasod.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/wonugoduludofasug.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f86fab15d079.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87119b2c630.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f8701775e7f9.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f871262f2c72.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1041587.mozfiles.com
- site-1037215.mozfiles.com
- site-1038973.mozfiles.com
- site-1036874.mozfiles.com
- cdn-cms.f-static.net
- wepugimi.weebly.com
- nudojafobedem.weebly.com
- povutepumik.weebly.com
- tajurasexir.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report