SUSPICIOUS — xalumojolawesasuko.pdf
SUSPICIOUS — xalumojolawesasuko.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
27e49622da04088166de92abbb3189dfc264b5b0251ece424063ba42033695a3 - SHA-1:
ae607dade98dddedf21a6d9428c1a65a1e5610ae - MD5:
ca37539ea3d1b6b96339c6154f731baa - ssdeep:
768:KgGzpD6poRhCvHPwCVxxF3tR6idUTPmrXxytPrSezI/NwrOcFqf7yyGYLhdE/TDh:XGFupLdUjmrktPrSV/ar0/GYLhu/TDRH - TLSH:
T18C33AFF32053ED4C7A9E5B17AEBA0169A18AD78AA036D79104CC372CE47C6FD3D10951 - Submitted as: xalumojolawesasuko.pdf
- File type: pdf · Size: 48950 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=bass%20buster%20guide%20service, https://cdn-cms.f-static.net/uploads/4365576/normal_5f87d47ce0716.pdf, https://cdn-cms.f-static.net/uploads/4366969/normal_5f88fe552e29e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=bass%20buster%20guide%20service
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f87d47ce0716.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f88fe552e29e.pdf
- https://cdn-cms.f-static.net/uploads/4373769/normal_5f895d0c2caaf.pdf
- https://cdn.shopify.com/s/files/1/0485/3320/9243/files/25790042916.pdf
- https://cdn.shopify.com/s/files/1/0427/8855/2870/files/64898726273.pdf
- https://cdn.shopify.com/s/files/1/0481/5624/6165/files/pufetelugit.pdf
- https://cdn.shopify.com/s/files/1/0432/3124/8539/files/jopegubudijobodiwifob.pdf
- https://cdn.shopify.com/s/files/1/0496/2723/4455/files/calendario_escolar_185_dias_2020.pdf
- https://cdn.shopify.com/s/files/1/0479/6855/1068/files/kaxewabetusobidafod.pdf
- https://cdn.shopify.com/s/files/1/0432/4560/0936/files/electrohome_usb_charging_alarm_clock_radio_manual.pdf
- https://cdn.shopify.com/s/files/1/0488/4473/4629/files/pusij.pdf
- https://cdn.shopify.com/s/files/1/0481/6997/5965/files/mobogenie_pro_3.2.13.4_latest_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0433/0523/8692/files/12942066134.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/9611777.pdf
- https://dagigokes.weebly.com/uploads/1/3/0/7/130739756/nodifogenimawo.pdf
- https://cdn.shopify.com/s/files/1/0432/8102/3140/files/all_over_but_the_shoutin_audiobook.pdf
- https://cdn.shopify.com/s/files/1/0499/7847/4664/files/i_thought_it_was_just_me_book.pdf
- https://cdn.shopify.com/s/files/1/0497/2511/2477/files/letture_italiano_facile.pdf
- https://cdn.shopify.com/s/files/1/0496/6976/7321/files/funny_magic_tricks_cards.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- medizagokitoni.weebly.com
- dagigokes.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report