SUSPICIOUS — zoxumumusan-xivab-sololeranazat-fupaboludifanil.pdf
SUSPICIOUS — zoxumumusan-xivab-sololeranazat-fupaboludifanil.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
5e7f8e8287c50fae15b05d0cf8195a3b131ab3b0b238f29cc6e9d3f4a1e9017a - SHA-1:
e43c19825a98557d00a90b266a29442e4633b55c - MD5:
5851748da37b76dbafbef12140bcf919 - ssdeep:
1536:hGFleFcaJs8o7D8YXY29pkVyvgc9YmDFe2:EFleeayLXJobWgHmD9 - TLSH:
T19333BFF3599BED4C7A87EB1399F70426558ACA8861339B501488773CC4BC6BDBF20960 - Submitted as: zoxumumusan-xivab-sololeranazat-fupaboludifanil.pdf
- File type: pdf · Size: 52181 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=john%20jairo%20velasquez%20wife%20alexandria, https://uploads.strikinglycdn.com/files/567be1f5-e834-465a-aadb-1424bb967df0/wivadilomukomamawegaxab.pdf, https://uploads.strikinglycdn.com/files/abdf8ddf-81fd-4c7f-ad3b-6a7707636049/tafesukopot.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=john%20jairo%20velasquez%20wife%20alexandria
- https://uploads.strikinglycdn.com/files/567be1f5-e834-465a-aadb-1424bb967df0/wivadilomukomamawegaxab.pdf
- https://uploads.strikinglycdn.com/files/abdf8ddf-81fd-4c7f-ad3b-6a7707636049/tafesukopot.pdf
- https://uploads.strikinglycdn.com/files/8fdf8312-498b-47a9-bbc9-ca1ff98b4006/36040381556.pdf
- https://uploads.strikinglycdn.com/files/5badd0a1-37e5-422f-8182-dd78bff949c6/73662431049.pdf
- https://uploads.strikinglycdn.com/files/4dac558b-3609-4342-8bfe-696cfd19cb04/57282227779.pdf
- https://uploads.strikinglycdn.com/files/369b079d-2e09-400b-b4bb-24f7ee84c312/34932375855.pdf
- https://cdn.shopify.com/s/files/1/0486/6939/3046/files/mozararerova.pdf
- https://cdn.shopify.com/s/files/1/0433/2129/5003/files/head_tennis_open_mousebreaker.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f86f415767c3.pdf
- https://cdn-cms.f-static.net/uploads/4366346/normal_5f8726b2117ce.pdf
- https://cdn-cms.f-static.net/uploads/4367299/normal_5f8754b97c8c8.pdf
- https://cdn.shopify.com/s/files/1/0497/8494/6850/files/46442188798.pdf
- https://cdn.shopify.com/s/files/1/0503/2080/1942/files/xasokawagetof.pdf
- https://cdn.shopify.com/s/files/1/0479/3588/1372/files/airtel_international_roaming_charges.pdf
- https://cdn.shopify.com/s/files/1/0440/8881/9864/files/lumupinilubetava.pdf
- https://cdn.shopify.com/s/files/1/0478/0038/5695/files/dotewetexusonoserosajavav.pdf
- https://uploads.strikinglycdn.com/files/24c19610-5b37-4cff-8921-55356896a0a9/71093066245.pdf
- https://uploads.strikinglycdn.com/files/ae35473b-2caf-43d1-95ef-5288b2c93c0f/41805177260.pdf
- https://uploads.strikinglycdn.com/files/f4f0ed3e-cf8e-43d5-b1b2-78d78cf601c4/48593384663.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report