SUSPICIOUS — lixusewasaxaxa_nosesijuro.pdf
SUSPICIOUS — lixusewasaxaxa_nosesijuro.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
43f2bbe1e8ba88e54f263e0ac47fb7d52d0ef23c660cab9d82bf9903fcce801a - SHA-1:
3f62456f5966da08f1bd94b8e19d873c7e15d94b - MD5:
c526a513808f81da383003a1851e0fb8 - ssdeep:
1536:OGFcpEsCINIcLcy4WWSmzc85aEqFX59KO76:3FcpEsChYcLSmzz5PqFJ9KJ - TLSH:
T11C34AEF3507BED4CBA8A8B436DA72455518CC3496272D3A088DCB76CD8BC1BDAE51820 - Submitted as: lixusewasaxaxa_nosesijuro.pdf
- File type: pdf · Size: 54930 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=acer%20swift%205%20review, https://cdn.shopify.com/s/files/1/0468/0243/6245/files/indominus_rex_toy_target.pdf, https://cdn.shopify.com/s/files/1/0501/5679/8117/files/6550177499.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=acer%20swift%205%20review
- https://cdn.shopify.com/s/files/1/0468/0243/6245/files/indominus_rex_toy_target.pdf
- https://cdn.shopify.com/s/files/1/0501/5679/8117/files/6550177499.pdf
- https://cdn.shopify.com/s/files/1/0499/8801/0134/files/fulinig.pdf
- https://cdn.shopify.com/s/files/1/0431/5794/6530/files/instructions_for_applying_vinyl_decal.pdf
- https://site-1048222.mozfiles.com/files/1048222/60379010751.pdf
- https://site-1039535.mozfiles.com/files/1039535/popomunoxerixapabezeme.pdf
- https://site-1038864.mozfiles.com/files/1038864/pegukaxireje.pdf
- https://site-1044155.mozfiles.com/files/1044155/xabigoxajat.pdf
- https://site-1041927.mozfiles.com/files/1041927/41040955183.pdf
- https://cdn-cms.f-static.net/uploads/4367296/normal_5f88a579498cc.pdf
- https://cdn-cms.f-static.net/uploads/4365657/normal_5f88bfc551c43.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/sobibizagavubuna.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/539333.pdf
- https://fagisidide.weebly.com/uploads/1/3/2/6/132682833/c1658fc589.pdf
- https://rabugotekinevod.weebly.com/uploads/1/3/1/8/131871666/6b97314b9e13d5.pdf
- https://pivozedotafi.weebly.com/uploads/1/3/1/0/131070355/2531199.pdf
- https://site-1044113.mozfiles.com/files/1044113/21603998067.pdf
- https://site-1042834.mozfiles.com/files/1042834/download_moto_rider_game_apk.pdf
- https://site-1036909.mozfiles.com/files/1036909/mumiwalekiseve.pdf
- https://site-1043669.mozfiles.com/files/1043669/tatofufif.pdf
- https://site-1038478.mozfiles.com/files/1038478/97298679920.pdf
- https://site-1036724.mozfiles.com/files/1036724/berefakejevodil.pdf
- https://site-1037866.mozfiles.com/files/1037866/sunezafojitomabil.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1048222.mozfiles.com
- site-1039535.mozfiles.com
- site-1038864.mozfiles.com
- site-1044155.mozfiles.com
- site-1041927.mozfiles.com
- cdn-cms.f-static.net
- jamuseramomuf.weebly.com
- nudojafobedem.weebly.com
- fagisidide.weebly.com
- rabugotekinevod.weebly.com
- pivozedotafi.weebly.com
- site-1044113.mozfiles.com
- site-1042834.mozfiles.com
- site-1036909.mozfiles.com
- site-1043669.mozfiles.com
- site-1038478.mozfiles.com
- site-1036724.mozfiles.com
- site-1037866.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report