SUSPICIOUS — pavukaniwewisi_vevudi_kafuzit.pdf
SUSPICIOUS — pavukaniwewisi_vevudi_kafuzit.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4630f5076dee50311a4d019458c1686d53f376765d542e2f9efc1924348c3821 - SHA-1:
54c39194489563bd60df88c55fefd54e9d070255 - MD5:
c7b6f8ab017c832abb8086bfae6086ea - ssdeep:
1536:njGFymrzR/yN8MRpuD61lHiqe5n8uD5WXb:nyFyksN8ka6bNe5n7D5O - TLSH:
T1B337D0F7419BDE4DBEC2BF639CAA50156088DB8CA126D62404CD363CD5BC6EEBE04611 - Submitted as: pavukaniwewisi_vevudi_kafuzit.pdf
- File type: pdf · Size: 70609 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=swtor%20sniper%20virulence%206.0%20guide, https://uploads.strikinglycdn.com/files/678d00fd-32d9-40ab-90b4-f9f97be00b86/sinofokobekopeno.pdf, https://lamuvoraraxuz.weebly.com/uploads/1/3/4/4/134486612/jifukademoj_pugodewunom_wokevelevalefon_fupimagik.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=swtor%20sniper%20virulence%206.0%20guide
- https://uploads.strikinglycdn.com/files/678d00fd-32d9-40ab-90b4-f9f97be00b86/sinofokobekopeno.pdf
- https://lamuvoraraxuz.weebly.com/uploads/1/3/4/4/134486612/jifukademoj_pugodewunom_wokevelevalefon_fupimagik.pdf
- https://uploads.strikinglycdn.com/files/a8aa6869-de86-43b7-9b6e-66af669d1479/26539746235.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f870e95db664.pdf
- https://uploads.strikinglycdn.com/files/27c451ca-21e2-49fb-9f1e-3ccc1fe4e590/archivos_de_audio_a_texto.pdf
- https://uploads.strikinglycdn.com/files/d69e90ca-0d60-4e92-bbc7-8d9812660e66/46369155886.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f8f39b044aad.pdf
- https://uploads.strikinglycdn.com/files/53f87fd6-d402-4bf4-8221-87e234f5a567/the_21_day_sugar_detox.pdf
- https://uploads.strikinglycdn.com/files/6892ba33-dd34-4530-a543-051b4c3bffcb/98343232426.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f970f81e8d30.pdf
- https://cdn-cms.f-static.net/uploads/4385217/normal_5f922f05020e8.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f881bc9450b6.pdf
- https://cdn-cms.f-static.net/uploads/4375886/normal_5f997a5535de5.pdf
- https://uploads.strikinglycdn.com/files/f07dcc63-24cb-4540-88f0-20ec452bf146/88569427992.pdf
- https://uploads.strikinglycdn.com/files/820f33ec-8284-4374-9bae-8036718b29a3/kemawajamalik.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- lamuvoraraxuz.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report