SUSPICIOUS — fosolujovatej-puxubawaratob-jamipemebujube-bipenu.pdf
SUSPICIOUS — fosolujovatej-puxubawaratob-jamipemebujube-bipenu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
33f920045c6185fdd8ccbdc9f8983411dede88192d859e74dfc8bdf1f190dafb - SHA-1:
8cc8d132cc795220af27a9ddbdf5664a7a37fb02 - MD5:
818878d6e0204d96ff9d2d04af5b228c - ssdeep:
768:6gGzpD8pZln2ifnYZTwFG5dkwZVENtsbbp:nGFIpXYZkY5dVotsvp - TLSH:
T1BA307BF310A7DE8C7A8BEB435EEB2559904AD789603297A00498772CC4BC7BD7F11960 - Submitted as: fosolujovatej-puxubawaratob-jamipemebujube-bipenu.pdf
- File type: pdf · Size: 37624 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=vallavanukku%20pullum%20aayudham%20full%20mo, https://uploads.strikinglycdn.com/files/77b4a0e9-9d75-4254-8ac5-478e78aaf1b7/52048886418.pdf, https://uploads.strikinglycdn.com/files/d2e18eb4-2f69-4885-adcf-b587ebfe954e/88609559477.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=vallavanukku%20pullum%20aayudham%20full%20mo
- https://uploads.strikinglycdn.com/files/77b4a0e9-9d75-4254-8ac5-478e78aaf1b7/52048886418.pdf
- https://uploads.strikinglycdn.com/files/d2e18eb4-2f69-4885-adcf-b587ebfe954e/88609559477.pdf
- https://uploads.strikinglycdn.com/files/f1ff892d-216c-470e-97e0-1ac4910cf430/48755450846.pdf
- https://uploads.strikinglycdn.com/files/34fad47f-c63e-4c28-93ec-447d4f3eaf5c/nazujejef.pdf
- https://uploads.strikinglycdn.com/files/358b84b0-b525-48fe-ba00-0357e7e409fc/nefiwuwonavirerokix.pdf
- https://site-1048550.mozfiles.com/files/1048550/jukawuwokakovosoxare.pdf
- https://site-1039320.mozfiles.com/files/1039320/82234791142.pdf
- https://site-1037267.mozfiles.com/files/1037267/torinowosibawidunu.pdf
- https://site-1048456.mozfiles.com/files/1048456/rixisudepofiri.pdf
- https://uploads.strikinglycdn.com/files/98f2bb40-a295-42c1-a7a4-2598e62168c1/tudikudizigulo.pdf
- https://uploads.strikinglycdn.com/files/6d7f6c30-0ffd-4090-8261-bd198829def3/jiledowigejaz.pdf
- https://uploads.strikinglycdn.com/files/e68dfcb2-5050-4a0a-9845-dcffe765450e/gutiz.pdf
- https://uploads.strikinglycdn.com/files/318a5fb2-e195-4b6f-b10a-320e77e936eb/tepunegabexateletezem.pdf
- https://site-1038954.mozfiles.com/files/1038954/30901238343.pdf
- https://site-1040056.mozfiles.com/files/1040056/26585632330.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/zanazanekoxel.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/kadijamiruvinugeno.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tiladejonu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1048550.mozfiles.com
- site-1039320.mozfiles.com
- site-1037267.mozfiles.com
- site-1048456.mozfiles.com
- site-1038954.mozfiles.com
- site-1040056.mozfiles.com
- bedizegoresupa.weebly.com
- dutitujazekap.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report