SUSPICIOUS — xulenemud.pdf
SUSPICIOUS — xulenemud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3236079a8bf358104060f5a25ce06410e39bb136ccc8f2c46ebb15c90a4095a2 - SHA-1:
87956ac7603dd4fac71d6c42e4431d0f06b8d6f2 - MD5:
c3b33e407b713ad4dbd569a8e4048185 - ssdeep:
768:ggGzpDgp/dbbMh87phQZ2IUvMZFmmR9cEvfG1Lz/6Fse2ggkcXt+SgZjEGMgp5du:tGF0p/F8//8h11kZSg1Z5dDVt2 - TLSH:
T132339FF35097ED8C7DC39F5399AA095860899BCC71368B90488CBA3DC47C67D6F209A1 - Submitted as: xulenemud.pdf
- File type: pdf · Size: 52282 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=conan+exiles+spreng+dr%25C3%25BCse+farmen, https://uploads.strikinglycdn.com/files/035f0d2b-286d-4bad-a04c-445188eb3c2e/45243777121.pdf, https://uploads.strikinglycdn.com/files/5ec54327-2a8a-48cd-b106-0ce20d251f3f/felijabofopofut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=conan+exiles+spreng+dr%25C3%25BCse+farmen
- https://uploads.strikinglycdn.com/files/035f0d2b-286d-4bad-a04c-445188eb3c2e/45243777121.pdf
- https://uploads.strikinglycdn.com/files/5ec54327-2a8a-48cd-b106-0ce20d251f3f/felijabofopofut.pdf
- https://uploads.strikinglycdn.com/files/f8b6fdb8-b501-42a8-9ec7-8c37b46f90b4/kebobubiwefu.pdf
- https://uploads.strikinglycdn.com/files/3ffd2b48-cb14-44b8-809d-b39ce0f03de0/56947023036.pdf
- https://uploads.strikinglycdn.com/files/338fb132-66de-4d2e-a8aa-5e6e016ac9d1/causas_del_fin_de_la_guerra_fria.pdf
- https://mumixopid.weebly.com/uploads/1/3/1/8/131872042/1566151.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/kopiwu_gotatumeturi_bovejixegas_vivikow.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/sefimas.pdf
- https://uploads.strikinglycdn.com/files/6c773a90-02d2-41c0-b48b-b295f1cab32c/36380805936.pdf
- https://uploads.strikinglycdn.com/files/d8201276-c87c-4b42-84c5-c4c1e5c11abd/free_os_x_software.pdf
- https://uploads.strikinglycdn.com/files/7968f6fd-364d-4806-83a0-21831890bd49/18502538655.pdf
- https://uploads.strikinglycdn.com/files/aeeab139-1af5-429b-bc1e-e61cb146c1c9/tirinha_com_adverbio_com_gabarito.pdf
- https://cdn-cms.f-static.net/uploads/4379038/normal_5f8a2d9e5b3c6.pdf
- https://cdn-cms.f-static.net/uploads/4378382/normal_5f8a1d9747b9b.pdf
- https://cdn-cms.f-static.net/uploads/4375073/normal_5f8a0de80b9d5.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f87404e72716.pdf
- https://cdn-cms.f-static.net/uploads/4373779/normal_5f88ebb2ce380.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f8839d6cb194.pdf
- https://cdn-cms.f-static.net/uploads/4371240/normal_5f889a80b24d6.pdf
- https://cdn-cms.f-static.net/uploads/4368495/normal_5f883c2192004.pdf
- https://cdn-cms.f-static.net/uploads/4377377/normal_5f8a1f96b5963.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- mumixopid.weebly.com
- keniwuki.weebly.com
- zoveponezewuda.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report