SUSPICIOUS — xesujexeminonewefuga.pdf
SUSPICIOUS — xesujexeminonewefuga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3c9a1bf92065f5e897a67d89ac308d81abf81eaaaf456602009f4764b7ea0cfb - SHA-1:
05dc3319881102e4541330902872c6b2b292e88c - MD5:
f46ae22a8c8c177ef63a0e27fabc69cc - ssdeep:
768:/gGzpDZpyG+B5Mh8yri0rcGXU12gt2FKpFHMDpmWcdv5qF+Y4wFCuWyvyCenhOF4:IGFVprOtnEQWchoX70uWyvXiIm7x - TLSH:
T111328EF350A7ED8C7B8AAF13ADAA1099214AD78CA03797A0488C777CC47C5BD6D50960 - Submitted as: xesujexeminonewefuga.pdf
- File type: pdf · Size: 47375 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=1999%20bryan%20street, https://cdn-cms.f-static.net/uploads/4367622/normal_5f8752358bb67.pdf, https://cdn-cms.f-static.net/uploads/4366327/normal_5f8717f217365.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=1999%20bryan%20street
- https://cdn-cms.f-static.net/uploads/4367622/normal_5f8752358bb67.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f8717f217365.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_5f8775f97fe26.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f86fce7decb1.pdf
- https://uploads.strikinglycdn.com/files/9ac857d6-521c-4ceb-8b34-8b98829c9097/37235045897.pdf
- https://uploads.strikinglycdn.com/files/db5db9ba-2df7-4760-8181-74048e7bfb64/97407424660.pdf
- https://uploads.strikinglycdn.com/files/04cd1255-2aad-490c-89ea-49ab5e1d0409/xelenubata.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f8774155cf56.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f8732ca51ba6.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f874cf914a49.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f871bbeed560.pdf
- https://site-1044148.mozfiles.com/files/1044148/lusupo.pdf
- https://site-1039737.mozfiles.com/files/1039737/80137784365.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7304884.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/tigosorivibisakoxu.pdf
- https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/gumupedi.pdf
- https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/f1a9c3021c21962.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/zevarezoj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1044148.mozfiles.com
- site-1039737.mozfiles.com
- genigudepa.weebly.com
- jemiwuwavaza.weebly.com
- lixaworone.weebly.com
- mogezisatizate.weebly.com
- babikovinemixe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report