SUSPICIOUS — woxetukiwino_mupizazetanev_wofigagidip.pdf
SUSPICIOUS — woxetukiwino_mupizazetanev_wofigagidip.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
31c6a8f196cc0c8ce71d964445a4f2a801ff9c274bcbd9226905b3a95fde9934 - SHA-1:
f057fed2a8438713a742b8b9f5a7a5f05a49001c - MD5:
2b9a484deb57e21b42e87b79c2e798d9 - ssdeep:
1536:lPGF2e2zUV3jTYPT/svNWaaqv5J5yhFK:l+F2edV3vWT/sVW5qx3yO - TLSH:
T1FB339EF3509BDE8C7ACB9B43ACB71195254AC78C72229B9440C8772CD5BC2BD6F10A61 - Submitted as: woxetukiwino_mupizazetanev_wofigagidip.pdf
- File type: pdf · Size: 50494 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=corre%C3%A7%C3%A3o%20palografico%20pdf, https://site-1038488.mozfiles.com/files/1038488/12745449259.pdf, https://site-1039795.mozfiles.com/files/1039795/10390808651.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=corre%C3%A7%C3%A3o%20palografico%20pdf
- https://site-1038488.mozfiles.com/files/1038488/12745449259.pdf
- https://site-1039795.mozfiles.com/files/1039795/10390808651.pdf
- https://site-1040600.mozfiles.com/files/1040600/mukusewumiwixoza.pdf
- https://cdn.shopify.com/s/files/1/0483/7628/3287/files/matchington_mansion_hack_app.pdf
- https://cdn.shopify.com/s/files/1/0428/6211/7031/files/hillsound_trail_crampon.pdf
- https://cdn.shopify.com/s/files/1/0433/9721/8471/files/29761478714.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f87365db08a9.pdf
- https://cdn-cms.f-static.net/uploads/4366642/normal_5f87bb5c6ce9d.pdf
- https://cdn-cms.f-static.net/uploads/4368224/normal_5f87a8f26e43e.pdf
- https://cdn-cms.f-static.net/uploads/4367919/normal_5f878283ad00e.pdf
- https://cdn-cms.f-static.net/uploads/4365545/normal_5f876eee7992c.pdf
- https://cdn-cms.f-static.net/uploads/4368219/normal_5f877407a9275.pdf
- https://cdn-cms.f-static.net/uploads/4367640/normal_5f874eb401dd2.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/4056517.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/8fd1a9303cb.pdf
- https://vibebivenef.weebly.com/uploads/1/3/1/4/131412032/mozonabipos.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/xefafimofaxeparekuji.pdf
- https://site-1039759.mozfiles.com/files/1039759/90879282766.pdf
- https://site-1037218.mozfiles.com/files/1037218/zurolukuxulesejis.pdf
- https://site-1048529.mozfiles.com/files/1048529/24054168508.pdf
- https://site-1043519.mozfiles.com/files/1043519/87942680897.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- site-1038488.mozfiles.com
- site-1039795.mozfiles.com
- site-1040600.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- dutitujazekap.weebly.com
- taxajadotediru.weebly.com
- vibebivenef.weebly.com
- mojivimimujovo.weebly.com
- site-1039759.mozfiles.com
- site-1037218.mozfiles.com
- site-1048529.mozfiles.com
- site-1043519.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report