SUSPICIOUS — dozezobibemoj_winenutulejexur_loxukiziguvofa_vufoxokatuz.pdf
SUSPICIOUS — dozezobibemoj_winenutulejexur_loxukiziguvofa_vufoxokatuz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
93ab339201a1222b7e2204ac3e40250638981587cad6cd417284edc75c6d110f - SHA-1:
05fba0c5575a3a103acb394931f96cc37dc924b0 - MD5:
01b2383ec5fbef0e3aabab3c0bfbc0b1 - ssdeep:
3072:uFupyjcqGfnkr2l3MuX8FnA1pJ1VE19xIr7tdAZmJZOp/ZiGuo+Kew:+omK/02pXXkA1pNcx67AZm2kJW - TLSH:
T1F03EF1F314E7DF0CB5CE6B436AA519A5104AC2CC6232D751A0CEAA5ED07CB9D2F00A57 - Submitted as: dozezobibemoj_winenutulejexur_loxukiziguvofa_vufoxokatuz.pdf
- File type: pdf · Size: 146484 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=beavis%20and%20butthead%20season%208, https://site-1043218.mozfiles.com/files/1043218/bakokarusokukuwafopiven.pdf, https://site-1040170.mozfiles.com/files/1040170/64866181874.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=beavis%20and%20butthead%20season%208
- https://site-1043218.mozfiles.com/files/1043218/bakokarusokukuwafopiven.pdf
- https://site-1040170.mozfiles.com/files/1040170/64866181874.pdf
- https://site-1039484.mozfiles.com/files/1039484/mimufasiniduwaxexisix.pdf
- https://site-1043120.mozfiles.com/files/1043120/31187915127.pdf
- https://site-1039830.mozfiles.com/files/1039830/23986372358.pdf
- https://uploads.strikinglycdn.com/files/59292846-d524-4a04-942c-a69bc0a511fa/38871523124.pdf
- https://uploads.strikinglycdn.com/files/1395aa93-5ac8-4d9d-8ee6-0672bac0f47f/refinusutozonuropop.pdf
- https://uploads.strikinglycdn.com/files/572b69ba-221e-4c90-9581-d34cf558f0e2/zojinopaxaj.pdf
- https://uploads.strikinglycdn.com/files/59ba2de4-75dd-41eb-baf4-5247f2e6cb81/31944111624.pdf
- https://uploads.strikinglycdn.com/files/c9aee9b1-d7d2-40e9-8428-b199dd340e9f/dikenodogaredigu.pdf
- https://uploads.strikinglycdn.com/files/e2387a54-3c3a-48c4-a3f5-79993cacbc3c/razovuboza.pdf
- https://uploads.strikinglycdn.com/files/ac59a779-7293-4b40-9bfb-3eeed77ee209/69494513093.pdf
- https://uploads.strikinglycdn.com/files/53ff1e8c-8a57-4cde-85ef-b5025b6909a4/pepobegovilox.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f877ba024993.pdf
- https://cdn-cms.f-static.net/uploads/4366949/normal_5f8741798ead6.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f87685a2e7cd.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/bigunurusipota_vovavubavuw_malolipesafa.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/f1dfc27.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/limekawavuv-fukif.pdf
- https://uploads.strikinglycdn.com/files/470a9ca3-923d-4a17-b386-ba964e9cf697/disuketisivovomelak.pdf
- https://uploads.strikinglycdn.com/files/b2289b2d-7113-4f2a-8ea4-1a3eb920fa9e/74192266225.pdf
- https://uploads.strikinglycdn.com/files/75be2366-323d-4ee9-8131-13591c40d389/segidabupitefamidemopevi.pdf
- https://uploads.strikinglycdn.com/files/9b72aa80-088a-4fa4-b513-00aa2c178f3e/29016431926.pdf
- https://uploads.strikinglycdn.com/files/54150067-833a-4fca-97ce-0db0e2168fbf/35501621783.pdf
Embedded domains
- gettraff.ru
- site-1043218.mozfiles.com
- site-1040170.mozfiles.com
- site-1039484.mozfiles.com
- site-1043120.mozfiles.com
- site-1039830.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- keniwuki.weebly.com
- jufaxexave.weebly.com
- rezizeme.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report