SUSPICIOUS — xazazivexubef.pdf
SUSPICIOUS — xazazivexubef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
67a8e02b528dca7baaed9ac45eaf9bd3ad32f9ea768936209d869a25d2a82f88 - SHA-1:
c105346e24b1fd7bd0f8294c12ed7373dc9ec5e8 - MD5:
4f5acfdaed2d716950286f4ed3ab9eeb - ssdeep:
768:ygGzpDXeaxtDu2rcv+AybhiRooXbioLEbnVZKXtUJelaPDans9PR5yeM1s:vGFzeSi6wLEjVRJeDnshRhM1s - TLSH:
T102327DF35097EC8C7ACF9F13A9AB115A6489C78D21339650449C3B2CC5BCAED6F10A61 - Submitted as: xazazivexubef.pdf
- File type: pdf · Size: 46092 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=what%20does%20not%20filtered%20by%20license%20mean, https://cdn.shopify.com/s/files/1/0433/8099/8298/files/15362942152.pdf, https://cdn.shopify.com/s/files/1/0436/2141/7123/files/wobaruximarojinunibigaxuz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=what%20does%20not%20filtered%20by%20license%20mean
- https://cdn.shopify.com/s/files/1/0433/8099/8298/files/15362942152.pdf
- https://cdn.shopify.com/s/files/1/0436/2141/7123/files/wobaruximarojinunibigaxuz.pdf
- https://cdn.shopify.com/s/files/1/0430/7877/9047/files/difference_between_polysemy_and_homonymy.pdf
- https://cdn.shopify.com/s/files/1/0497/1518/3777/files/14616522920.pdf
- https://cdn.shopify.com/s/files/1/0483/3997/6345/files/new_balance_806_vs_1006.pdf
- https://cdn-cms.f-static.net/uploads/4368752/normal_5f8a5433033e9.pdf
- https://cdn-cms.f-static.net/uploads/4370265/normal_5f8c5b4086cd3.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f894d43f0fbb.pdf
- https://cdn.shopify.com/s/files/1/0485/6089/8213/files/que_son_los_productos_notables_y_su_utilidad.pdf
- https://cdn.shopify.com/s/files/1/0498/0758/9530/files/94280237896.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/gipipamiv.pdf
- https://vunixumo.weebly.com/uploads/1/3/1/4/131453253/3ac78b13b13.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/xanixaja.pdf
- https://kesevaze.weebly.com/uploads/1/3/1/3/131383297/dufaderosovebexa.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/138303.pdf
- https://xivenisulebitok.weebly.com/uploads/1/3/1/3/131378814/ruxabu-figuvazeruzujef-xoxujewalelif.pdf
- https://fopimakalegej.weebly.com/uploads/1/3/0/7/130738542/wofuzelos_fuvevalalorobol_gagituv_sukubabojuxaris.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/zemokivajuf.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xereromejiv-koxozirusoror-moxonujis.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/bedenowarevof.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/fa45cf1873c.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- xojerajap.weebly.com
- vunixumo.weebly.com
- bizumoku.weebly.com
- kesevaze.weebly.com
- rakamukomegu.weebly.com
- xivenisulebitok.weebly.com
- fopimakalegej.weebly.com
- xojisige.weebly.com
- dutitujazekap.weebly.com
- fuparududewon.weebly.com
- lipowuripipu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report