SUSPICIOUS — piloxub_vaxemejelan_kozepos.pdf
SUSPICIOUS — piloxub_vaxemejelan_kozepos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7ff2fa82717239cec75f8e8fd86fd02cbc385ea24162b775550a5c5b8d3c361c - SHA-1:
fa259c6d786475dc25a64eb192a1d6786dc91310 - MD5:
1a7a687e22c77ea70ced3150cc77a8ad - ssdeep:
768:WgGzpDVpArUtN/Ffh/aWFTxCiS9bLxugxo/xKGYxWyWw7RJygD1kFj:DGFhpAr+mb0gxcEGpXgZkFj - TLSH:
T1D7327CF300A3ED4C798BDF03A9EB155D9449D249A173E6A150893B2CC17C6BDBF20A60 - Submitted as: piloxub_vaxemejelan_kozepos.pdf
- File type: pdf · Size: 44260 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=bananadine%20como%20para%20fazer, https://site-1040041.mozfiles.com/files/1040041/41562431355.pdf, https://site-1037276.mozfiles.com/files/1037276/tijat.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=bananadine%20como%20para%20fazer
- https://site-1040041.mozfiles.com/files/1040041/41562431355.pdf
- https://site-1037276.mozfiles.com/files/1037276/tijat.pdf
- https://site-1037273.mozfiles.com/files/1037273/megabexazezojeduku.pdf
- https://site-1043249.mozfiles.com/files/1043249/webevukajuval.pdf
- https://site-1044053.mozfiles.com/files/1044053/kolav.pdf
- https://site-1038438.mozfiles.com/files/1038438/podadoxin.pdf
- https://site-1048442.mozfiles.com/files/1048442/20352427875.pdf
- https://site-1042832.mozfiles.com/files/1042832/jizinuzenetuxogejis.pdf
- https://site-1043453.mozfiles.com/files/1043453/72073538283.pdf
- https://uploads.strikinglycdn.com/files/7f5d932c-fc1c-4689-956b-ed8c685138aa/pusemititefotur.pdf
- https://uploads.strikinglycdn.com/files/67802c0b-dbbb-4d8a-ada3-62923f046e18/31966313687.pdf
- https://cdn-cms.f-static.net/uploads/4366676/normal_5f873017c22c4.pdf
- https://cdn-cms.f-static.net/uploads/4367635/normal_5f875040b4fd5.pdf
- https://cdn-cms.f-static.net/uploads/4366305/normal_5f872b3ae0116.pdf
- https://cdn-cms.f-static.net/uploads/4366623/normal_5f873d50b4b1e.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f875f0fb8201.pdf
- https://cdn-cms.f-static.net/uploads/4366958/normal_5f8767295d69e.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f8759fbe0233.pdf
- https://cdn.shopify.com/s/files/1/0501/6272/9125/files/bdo_guide_to_going_public.pdf
- https://cdn.shopify.com/s/files/1/0435/5833/8715/files/bakosijasajadiwakexoke.pdf
- https://cdn.shopify.com/s/files/1/0432/7292/9435/files/elegant_objects_free_download.pdf
- https://cdn.shopify.com/s/files/1/0434/0717/9941/files/massfx_tires_forum.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- site-1040041.mozfiles.com
- site-1037276.mozfiles.com
- site-1037273.mozfiles.com
- site-1043249.mozfiles.com
- site-1044053.mozfiles.com
- site-1038438.mozfiles.com
- site-1048442.mozfiles.com
- site-1042832.mozfiles.com
- site-1043453.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report