SUSPICIOUS — xodubexexaki.pdf
SUSPICIOUS — xodubexexaki.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8cf822ff66cd7544cfa219856a6e767484e43f918c5fe180a3af29a5847ea0f7 - SHA-1:
84dfd3af750da3e056c0fb2de5210edcb6bb280f - MD5:
ef5b08f523fd31a6e108949b39f06334 - ssdeep:
1536:TGF8NHXEeA9eF4wyK+uUbegLE72FSWE5fJltIs2:iF8N0e10NbeqE7ySxq - TLSH:
T19E349EF751D7DC8C3A8BEB03AAA710696106D64C722796909598763CC4BCAFC7F20921 - Submitted as: xodubexexaki.pdf
- File type: pdf · Size: 54414 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=adobe+acrobat+convert+pdf+to+word+free+trial, http://files.melindaluthinlaw.com/uploads/1/3/0/8/130814714/4236779.pdf, http://vopofaket.penultimatephotos.com/uploads/1/3/0/9/130969264/kuxijapufidugoj-jomawizakog-zejejegekizudi-setobu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=adobe+acrobat+convert+pdf+to+word+free+trial
- http://files.melindaluthinlaw.com/uploads/1/3/0/8/130814714/4236779.pdf
- http://vopofaket.penultimatephotos.com/uploads/1/3/0/9/130969264/kuxijapufidugoj-jomawizakog-zejejegekizudi-setobu.pdf
- http://regeb.lakelandplayers.net/uploads/1/3/1/4/131406840/jerudutivilibipe.pdf
- http://regeka.miramarbarra.co.za/uploads/1/3/1/1/131164250/sojesap.pdf
- https://uploads.strikinglycdn.com/files/f7487f82-35d1-4070-8ac6-c10e8d5bcb0d/55109080201.pdf
- https://uploads.strikinglycdn.com/files/c9b137f9-8832-4564-801d-7a2dd08c3996/66239363879.pdf
- https://uploads.strikinglycdn.com/files/b2d5771b-3c12-4b93-9bb9-b9fbad651d88/19289740639.pdf
- https://uploads.strikinglycdn.com/files/ddcde369-1dd4-4d4b-9db1-56833f9ac13e/bezanorujumuzaxoxuleto.pdf
- https://uploads.strikinglycdn.com/files/6b73e5d7-9cc5-4da5-8af7-0b31a76b3c33/81830433072.pdf
- https://uploads.strikinglycdn.com/files/6a4b8d55-ef6a-4d25-84d0-a54f27bca7f5/22123441838.pdf
- https://uploads.strikinglycdn.com/files/3e8be4e9-a413-4147-b0db-d429e43c9e16/8637597150.pdf
- https://uploads.strikinglycdn.com/files/be102f09-b1dd-48f5-9a47-5d4f6e0dd592/doxuwaxakavupudo.pdf
- http://files.kellypiliouras.com/uploads/1/3/2/6/132695301/7871457.pdf
- http://nasuwe.playittodaygames.com/uploads/1/3/0/7/130775545/durorajex.pdf
- http://xilufitos.thelifeatthehelm.com/uploads/1/3/1/4/131482851/jogip.pdf
- http://jedip.chemistrywithdrjames.com/uploads/1/3/1/4/131406412/d450eabb1852.pdf
- http://popixe.soilandsun.co.uk/uploads/1/3/2/3/132303320/6088485.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.melindaluthinlaw.com
- vopofaket.penultimatephotos.com
- regeb.lakelandplayers.net
- regeka.miramarbarra.co.za
- uploads.strikinglycdn.com
- files.kellypiliouras.com
- nasuwe.playittodaygames.com
- xilufitos.thelifeatthehelm.com
- jedip.chemistrywithdrjames.com
- popixe.soilandsun.co.uk
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report