SUSPICIOUS — gobunaxobu.pdf
SUSPICIOUS — gobunaxobu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3da8810b1056e66fc4f327573501d56635cc20526bb73f461477f82629effb1c - SHA-1:
993adc71bc79b071c5ead41052f70011548befd7 - MD5:
ce09089f1f9b49b1c26cfb0c593f17cc - ssdeep:
768:3gGzpDcpar2/MH3GxRmvOq6+7ODiyI46csSAlONSqpwQEV0GF9O:QGFgpaemWBDqfHONSKYZF9O - TLSH:
T1DD327DF751E7ED8C768EAB139EAA055C5189C78CB027D76008C8762DC0BCABD7E10652 - Submitted as: gobunaxobu.pdf
- File type: pdf · Size: 44861 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=acls%20bradycardia%20pdf, https://uploads.strikinglycdn.com/files/61846dd6-d4fe-4130-8ece-528723ee3811/vonijidajalileju.pdf, https://uploads.strikinglycdn.com/files/a121f78d-0a66-4098-a9f0-9e6be92808a0/xoxonojewogotukijuxigeki.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=acls%20bradycardia%20pdf
- https://uploads.strikinglycdn.com/files/61846dd6-d4fe-4130-8ece-528723ee3811/vonijidajalileju.pdf
- https://uploads.strikinglycdn.com/files/a121f78d-0a66-4098-a9f0-9e6be92808a0/xoxonojewogotukijuxigeki.pdf
- https://uploads.strikinglycdn.com/files/55452987-e47a-4622-940f-23239e838950/87471014508.pdf
- https://uploads.strikinglycdn.com/files/b87fd416-0580-4f82-bc68-b17c1c6f8739/12122914170.pdf
- https://uploads.strikinglycdn.com/files/9487425e-7f15-4254-b4d0-f459c7c1e094/the_norton_introduction_to_literature_shorter_12th_edition_free.pdf
- https://cdn-cms.f-static.net/uploads/4369315/normal_5f8d8b0949a72.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/zizekazaribibobosa.pdf
- https://xilorufanil.weebly.com/uploads/1/3/0/7/130739938/fomigupubo-remobadapu.pdf
- https://dumejolizaxoko.weebly.com/uploads/1/3/0/8/130814858/kenogene_duzasibug_rotalarux.pdf
- https://folatidaxewurel.weebly.com/uploads/1/3/4/3/134317863/493f967.pdf
- https://cdn.shopify.com/s/files/1/0477/4353/3212/files/catia_tutorial_download.pdf
- https://cdn.shopify.com/s/files/1/0431/2308/1378/files/8855739395.pdf
- https://cdn.shopify.com/s/files/1/0457/5254/9532/files/44639241886.pdf
- https://cdn.shopify.com/s/files/1/0268/8394/8740/files/rojiriloxiwuruzobo.pdf
- https://cdn.shopify.com/s/files/1/0434/6544/1445/files/wikonoxevakedokojegi.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/daseduzuvejilu.pdf
- https://risidetumul.weebly.com/uploads/1/3/4/3/134320066/mulusijof.pdf
- https://vufufibujirefe.weebly.com/uploads/1/3/4/3/134355905/xakelunape.pdf
- https://tedovuja.weebly.com/uploads/1/3/4/4/134465286/budopiwidid.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf
- https://cdn-cms.f-static.net/uploads/4404983/normal_5f971b006ccb5.pdf
- https://cdn-cms.f-static.net/uploads/4379231/normal_5f8c9a260363a.pdf
- https://cdn-cms.f-static.net/uploads/4370270/normal_5f8c7f374c59e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- tivakoxidedopa.weebly.com
- xilorufanil.weebly.com
- dumejolizaxoko.weebly.com
- folatidaxewurel.weebly.com
- cdn.shopify.com
- xebikazogede.weebly.com
- risidetumul.weebly.com
- vufufibujirefe.weebly.com
- tedovuja.weebly.com
- dimaxafazeza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report