SUSPICIOUS — zidirojibasubi-xebubeneretopoz-pigekosap-dikasukotube.pdf
SUSPICIOUS — zidirojibasubi-xebubeneretopoz-pigekosap-dikasukotube.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
6121681df68d58d9671f878d24a205690a0af4553eb4ce0b0322ce4ec1542817 - SHA-1:
8c8e9b2683698ce76b16f3029abae20db3bad9d4 - MD5:
74f6badc694bcd667b7e9af291ab3f05 - ssdeep:
768:TgGzpDQ5u6G/OOL/wZMY19mnH5mF5T5oNX5MuGqF:sGFk5s/K1gZmFN4X5bGqF - TLSH:
T16631AFF311A7EE4C77869B139DEA045D184AD389A1329A7005C93B3CC8BCBED6E55430 - Submitted as: zidirojibasubi-xebubeneretopoz-pigekosap-dikasukotube.pdf
- File type: pdf · Size: 41056 bytes
- Verdict: suspicious (44/100)
Detections (2 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffmen.ru/wb?keyword=kirby%20nightmare%20in%20dreamland%20unblocked%20game, https://cdn-cms.f-static.net/uploads/4368466/normal_5f9e0edadc528.pdf, https://cdn-cms.f-static.net/uploads/4403421/normal_5f97c95e26299.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/wb?keyword=kirby%20nightmare%20in%20dreamland%20unblocked%20game
- https://wotenopofe.files.wordpress.com/2020/11/budixaw.pdf
- https://sizixef.files.wordpress.com/2020/11/23789597695.pdf
- https://suvarofora.files.wordpress.com/2020/11/lodebukiworidu.pdf
- https://cdn-cms.f-static.net/uploads/4368466/normal_5f9e0edadc528.pdf
- https://s3.amazonaws.com/mijedusovineti/sososonepamusofoke.pdf
- https://cdn-cms.f-static.net/uploads/4403421/normal_5f97c95e26299.pdf
- https://s3.amazonaws.com/migivewuwe/anova_estatistica.pdf
- https://s3.amazonaws.com/sukedil/section_38_2_the_process_of_digestion_answers.pdf
- https://junafoxotoroj.weebly.com/uploads/1/3/0/7/130738975/f02efee.pdf
- https://gazitagoro.weebly.com/uploads/1/3/4/0/134016873/3686679.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- wotenopofe.files.wordpress.com
- sizixef.files.wordpress.com
- suvarofora.files.wordpress.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- junafoxotoroj.weebly.com
- gazitagoro.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report