SUSPICIOUS — xekamujovuwalogetef.pdf
SUSPICIOUS — xekamujovuwalogetef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
61067c19cad3c5b18b967c4938eb458f0f888c1dc549268ebe14090467d0f118 - SHA-1:
5284dcdae0c0f67b806adfec728e6b29d6c59826 - MD5:
2bd547200d15737ea1bae2348f20fd76 - ssdeep:
768:ugGzpDtp4PkX5uuEIwoMM+vfIcLGCBqHK48srdTmt/CDVrIA9y9Mda2:LGFRpYfL3BKThpTmN+VrR9fda2 - TLSH:
T13D316CF350A7DE4C798BEF036EBA291D9589D7895132A7A0448C672DC4BC7BD3E00990 - Submitted as: xekamujovuwalogetef.pdf
- File type: pdf · Size: 40917 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=sandesh+epaper+vadodara+today+pdf, https://uploads.strikinglycdn.com/files/9c65f0d9-3d6c-4fe8-b5f6-cbd9145922ff/rebemafisulakosuganireliv.pdf, https://uploads.strikinglycdn.com/files/e1981e6f-ab62-4d9c-869e-0e60a33f7eb5/lokezowejutoxefubigaluj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=sandesh+epaper+vadodara+today+pdf
- https://uploads.strikinglycdn.com/files/9c65f0d9-3d6c-4fe8-b5f6-cbd9145922ff/rebemafisulakosuganireliv.pdf
- https://uploads.strikinglycdn.com/files/e1981e6f-ab62-4d9c-869e-0e60a33f7eb5/lokezowejutoxefubigaluj.pdf
- https://uploads.strikinglycdn.com/files/5ad0e743-498e-46d5-9414-e8b0dc9541df/fewetujojov.pdf
- https://uploads.strikinglycdn.com/files/2b7f9f74-1a94-4691-8d53-fd5f4cd3ed10/sadejepizax.pdf
- https://kafasomawupi.weebly.com/uploads/1/3/0/7/130775431/2845903.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/roruj-fegedevovelere-zexomojikazi-rewubujelem.pdf
- https://uploads.strikinglycdn.com/files/0405247a-4983-4aae-8e6c-31735eebeccb/63089982811.pdf
- https://uploads.strikinglycdn.com/files/269312b0-4845-43d0-83cf-21578d3bbbbd/76673033145.pdf
- https://uploads.strikinglycdn.com/files/3616f39b-e23a-43e6-a2c0-406670205a18/91599698544.pdf
- https://uploads.strikinglycdn.com/files/eb570c9f-df75-4931-92b2-e70f5ea91cc9/nerufarezutapujuxowuxiw.pdf
- https://uploads.strikinglycdn.com/files/e09573ec-150f-49dd-b08a-aa37e979eba8/essentially_perfect_fit_summary_m.pdf
- https://uploads.strikinglycdn.com/files/7441d59a-14a1-4fcb-be17-107ddf83e6aa/20188714535.pdf
- https://uploads.strikinglycdn.com/files/49204856-d84d-4cf6-8ee7-7f2a39f99657/bizebunapagosinejafe.pdf
- https://uploads.strikinglycdn.com/files/7d7c976d-a6fb-4917-b8e1-1aca31fa7008/rogupimuvazu.pdf
- https://cdn-cms.f-static.net/uploads/4368223/normal_5f88304ec3d47.pdf
- https://cdn-cms.f-static.net/uploads/4377377/normal_5f8a1c0eb7f06.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f86faad50392.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f8a0e187a010.pdf
- https://cdn-cms.f-static.net/uploads/4366324/normal_5f870d9621f6c.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f88c4259748b.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f887bb62dc39.pdf
- https://cdn-cms.f-static.net/uploads/4377377/normal_5f8a130c2d78f.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f8722a4d9404.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f875724818e3.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- kafasomawupi.weebly.com
- guwomenod.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report