SUSPICIOUS — movutomu-koberu-bifagefare-bimimepaxos.pdf
SUSPICIOUS — movutomu-koberu-bifagefare-bimimepaxos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
710ca6d072cf06bca98956be28615a323900a4f6d0f80dd18cb7f89500845e89 - SHA-1:
4e542b2a3166a77d735b778dc9f91d431534588c - MD5:
8f6c0c167464ae929fb3299558c4935a - ssdeep:
768:NgGzpDNpPu3tlqnxXa5RFzBQkWoAQ9+fhj9nLuJY0Gzb1eTEoAU1F+P8GP:uGFRpPePzW7hj1LuJY0G0TAKFW8GP - TLSH:
T13033AFF710D7DC8C7A8B5F439DBB10695299C648B13697944888776CC07C2BDBF60990 - Submitted as: movutomu-koberu-bifagefare-bimimepaxos.pdf
- File type: pdf · Size: 50326 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=gerza%20dinamicas%20de%20comunicacion%20grup, https://uploads.strikinglycdn.com/files/37e8cf41-5a2e-439e-b194-45b7b2427ada/rusanederimigenaleb.pdf, https://uploads.strikinglycdn.com/files/639110f8-a248-4f92-bc43-a8d389d81240/60221604070.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=gerza%20dinamicas%20de%20comunicacion%20grup
- https://uploads.strikinglycdn.com/files/37e8cf41-5a2e-439e-b194-45b7b2427ada/rusanederimigenaleb.pdf
- https://uploads.strikinglycdn.com/files/639110f8-a248-4f92-bc43-a8d389d81240/60221604070.pdf
- https://uploads.strikinglycdn.com/files/79c91c56-bd91-411d-9380-6db19286a6b2/71043510758.pdf
- https://uploads.strikinglycdn.com/files/6f7c1a63-75cf-4ba3-99ce-85195e054f7c/wizixiwaxupuwo.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f871036b69e1.pdf
- https://site-1038460.mozfiles.com/files/1038460/vonanofe.pdf
- https://site-1042009.mozfiles.com/files/1042009/matug.pdf
- https://site-1039529.mozfiles.com/files/1039529/44362419386.pdf
- https://site-1043646.mozfiles.com/files/1043646/google_translate_apk_offline_for_pc.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f86fc24db4ba.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f8704dca56dc.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f86f8f64b370.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f86f651ce858.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f87132cab59d.pdf
- https://uploads.strikinglycdn.com/files/b37a9994-24dc-4dc9-98bd-53a6615f4d51/samufi.pdf
- https://uploads.strikinglycdn.com/files/10f6aee2-b876-4a0d-a6a1-60c14ee824a3/kexazajulewif.pdf
- https://site-1041677.mozfiles.com/files/1041677/86948465234.pdf
- https://site-1042498.mozfiles.com/files/1042498/taxurijojirarozapulapar.pdf
- https://site-1040506.mozfiles.com/files/1040506/janisajenajorimakuxonamif.pdf
- https://site-1037028.mozfiles.com/files/1037028/davejep.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1038460.mozfiles.com
- site-1042009.mozfiles.com
- site-1039529.mozfiles.com
- site-1043646.mozfiles.com
- site-1041677.mozfiles.com
- site-1042498.mozfiles.com
- site-1040506.mozfiles.com
- site-1037028.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report