SUSPICIOUS — bowefefedefafiburosaro.pdf
SUSPICIOUS — bowefefedefafiburosaro.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
32b3c038ace64b495a014af09f8ebd2fd43ac57c975cdebef07a83180a638613 - SHA-1:
665243990db5dbccbe5e4124673272f191290942 - MD5:
9b13f1e0e84ce1ab2f280d42360f3136 - ssdeep:
768:vgGzpDtaJ9iY7owXifCaUcJfQfhjkJCorDaEw4FdIko59CVjJF3XsqG/COVx2:YGFhaJ8AowXipUcJ6+1PZo59o4COf2 - TLSH:
T1EA329DF350B7ED4C7ACBAB135EEA256D904697886172A6240888777CC1BC3FE7E04521 - Submitted as: bowefefedefafiburosaro.pdf
- File type: pdf · Size: 47023 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=convert+word+2020+to+high+resolution+pdf, http://zawakexar.hollywoodpassionplay.com/uploads/1/3/2/7/132740351/6353818.pdf, http://files.paulysburgers.com/uploads/1/3/1/4/131437308/bobijitidenupo_dilinefonajufe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=convert+word+2020+to+high+resolution+pdf
- http://zawakexar.hollywoodpassionplay.com/uploads/1/3/2/7/132740351/6353818.pdf
- http://files.paulysburgers.com/uploads/1/3/1/4/131437308/bobijitidenupo_dilinefonajufe.pdf
- http://fogirizax.mitchadvent.com/uploads/1/3/1/6/131637046/tajujisokifa_gojedomobeke.pdf
- http://files.margieflores.com/uploads/1/3/1/3/131383581/6568581.pdf
- http://jetilo.valuedlives.co.uk/uploads/1/3/2/7/132740412/rupoziriwuj_xebupapaz_vetazigubaxeku.pdf
- http://salenad.kalaestes.com/uploads/1/3/0/8/130814297/diwepoge.pdf
- http://fuvas.small-product-photography.com/uploads/1/3/0/8/130814669/9272704.pdf
- http://files.donnawickham.com/uploads/1/3/2/8/132815731/501f3f908c.pdf
- http://files.countrymeadows2.com/uploads/1/3/0/8/130874360/vokekerodelin-pimapuxesaxu-fajedezuf.pdf
- http://velovemux.digthyself.com/uploads/1/3/0/7/130739124/mejinu.pdf
- https://site-1038882.mozfiles.com/files/1038882/63793356292.pdf
- https://site-1040974.mozfiles.com/files/1040974/37368666980.pdf
- https://site-1037122.mozfiles.com/files/1037122/78099070576.pdf
- https://site-1036830.mozfiles.com/files/1036830/kajivenosigedujupabi.pdf
- https://cdn.shopify.com/s/files/1/0435/5912/5153/files/nivitugevidomuzafuvafox.pdf
- https://cdn.shopify.com/s/files/1/0478/4226/3199/files/wards_science_blood_typing_lab_answers.pdf
- https://cdn.shopify.com/s/files/1/0427/7954/1671/files/how_to_gift_robux_without_a_group.pdf
- https://cdn.shopify.com/s/files/1/0480/8982/5443/files/baby_trend_expedition_sx_manual.pdf
- https://cdn.shopify.com/s/files/1/0485/2898/2171/files/convertir_kilometros_a_millas_en_pseint.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- zawakexar.hollywoodpassionplay.com
- files.paulysburgers.com
- fogirizax.mitchadvent.com
- files.margieflores.com
- jetilo.valuedlives.co.uk
- salenad.kalaestes.com
- fuvas.small-product-photography.com
- files.donnawickham.com
- files.countrymeadows2.com
- velovemux.digthyself.com
- site-1038882.mozfiles.com
- site-1040974.mozfiles.com
- site-1037122.mozfiles.com
- site-1036830.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report