SUSPICIOUS — tikewutoxawip-xeperebe-linejav.pdf
SUSPICIOUS — tikewutoxawip-xeperebe-linejav.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3a4275899113201da49b007f2980c8894d3b821e2cd2bcb958c1ed2eb40b972d - SHA-1:
5051b89af1ca6d75398fff0bcbe1ce238090ab9d - MD5:
6168e9a29638cc4cb78f1837af940f86 - ssdeep:
768:SgGzpDre4HHSgjv9eQYPr0QR8SXXOsTDgyva2T5VQYrhza4p6TW+RMIT/ilPdFd9:PGFXeQgQYP/R8SX+IDgyvLoYtzh+eOkD - TLSH:
T1E7337EF714E7DD8C7A8A6B43EDB7219A608AC3886136E7904488776ED1BC97D2E00D50 - Submitted as: tikewutoxawip-xeperebe-linejav.pdf
- File type: pdf · Size: 48568 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=cardfight%20vanguard%20simulator, https://uploads.strikinglycdn.com/files/b19401cf-feef-49c6-839c-f0bdc2ee0f59/xamenarovid.pdf, https://uploads.strikinglycdn.com/files/ee1e7aaa-6ff2-449b-bf05-8fd46dcf3191/82006800044.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=cardfight%20vanguard%20simulator
- https://uploads.strikinglycdn.com/files/b19401cf-feef-49c6-839c-f0bdc2ee0f59/xamenarovid.pdf
- https://uploads.strikinglycdn.com/files/ee1e7aaa-6ff2-449b-bf05-8fd46dcf3191/82006800044.pdf
- https://uploads.strikinglycdn.com/files/e25bd736-8fa8-4b28-ad27-1eea188641a6/pakuzerugolajelisat.pdf
- https://uploads.strikinglycdn.com/files/ba41cf07-1a9d-4ff5-818b-36901c146f86/zumudekudewupo.pdf
- https://site-1043091.mozfiles.com/files/1043091/13330181225.pdf
- https://site-1038679.mozfiles.com/files/1038679/52567073173.pdf
- https://site-1037094.mozfiles.com/files/1037094/xozefotejikik.pdf
- https://site-1038969.mozfiles.com/files/1038969/fipobexusiwazos.pdf
- https://site-1037086.mozfiles.com/files/1037086/wupedopufakamoved.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/dafujivilisig-jajetux.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ramugimexixepaba.pdf
- https://uploads.strikinglycdn.com/files/8beec96c-764d-4e12-a9ad-d2adf6c3c713/dafemu.pdf
- https://uploads.strikinglycdn.com/files/f3f956a0-3f91-4d29-a98e-99b5cbb73cd4/mofetofalitiwopegumused.pdf
- https://uploads.strikinglycdn.com/files/f4ea6db5-4e98-42e5-bb7b-25fa773e52f6/sazeviw.pdf
- https://uploads.strikinglycdn.com/files/be0dc3e9-6903-48ee-8d27-0f5730b078eb/nerifefotu.pdf
- https://uploads.strikinglycdn.com/files/322b3e40-1562-452d-b4f5-baa666e35bdf/95961806564.pdf
- https://uploads.strikinglycdn.com/files/df1634e4-93d6-44e3-9b71-e4ab8b9bd3f1/61328038791.pdf
- https://uploads.strikinglycdn.com/files/d8b917ec-bdfc-4a8a-82b9-a74debb9cdb4/sefazexanezewuni.pdf
- https://uploads.strikinglycdn.com/files/38fb8f9e-f62a-4020-bef9-01fe0a3535a2/52967255289.pdf
- https://uploads.strikinglycdn.com/files/83e3a34f-78ce-45b9-8bc1-e987c94570d5/68262670098.pdf
- https://uploads.strikinglycdn.com/files/f7d018c8-d14d-4ee5-a85b-69d9cbc5838c/18301309340.pdf
- https://uploads.strikinglycdn.com/files/2d636b8f-e6e8-4cae-9bc0-55c3207e4366/33519674638.pdf
- https://uploads.strikinglycdn.com/files/5903cbc3-b509-41c9-a772-f713e50a2bf3/45773307611.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1043091.mozfiles.com
- site-1038679.mozfiles.com
- site-1037094.mozfiles.com
- site-1038969.mozfiles.com
- site-1037086.mozfiles.com
- vuxozajuje.weebly.com
- sesuwulot.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report