MALICIOUS — zofaf_nenepo_pudos_lemubowakomexul.pdf
MALICIOUS — zofaf_nenepo_pudos_lemubowakomexul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
9886942096889ce5b798ae3a0d641f2eacc938f20bfa57b4a83d646a0c8f8be6 - SHA-1:
ff74061a6dd7d7e6b95b433e30c8a3d85681e242 - MD5:
9b0a0c140f0a0820163e47c999f6ca09 - ssdeep:
768:A9gGzpD0o1S37mfKNa5F3h0KXeYe8Wilc1zRr67jieLEt8761A4ICy0:A+GFgHTWZhhOsq1zpSoytCy0 - TLSH:
T15D319EF3945BEE8C7787AF03AAE514595189DAC87033966018D8776CC8FC6FC6E00962 - Submitted as: zofaf_nenepo_pudos_lemubowakomexul.pdf
- File type: pdf · Size: 40469 bytes
- Verdict: malicious (70/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=baleno%20automatic%20vs%20manual%20mileage, https://cdn-cms.f-static.net/uploads/4403143/normal_5f94ffb3abc34.pdf, https://uploads.strikinglycdn.com/files/9e26a3fd-3934-4848-acfd-f289746b17fc/viliwekiw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=baleno%20automatic%20vs%20manual%20mileage
- https://cdn-cms.f-static.net/uploads/4403143/normal_5f94ffb3abc34.pdf
- https://uploads.strikinglycdn.com/files/9e26a3fd-3934-4848-acfd-f289746b17fc/viliwekiw.pdf
- https://s3.amazonaws.com/lopazura/sharper_image_true_wireless_earbuds.pdf
- https://uploads.strikinglycdn.com/files/84e8cd21-1db3-4ebc-bd0c-26d6abbab8da/61280020173.pdf
- https://uploads.strikinglycdn.com/files/7ee031da-cc96-4513-9b10-c7b5d67171ef/chariots_of_fire_piano_sheet_music.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f913559d1a8c.pdf
- https://juvikenozenukun.weebly.com/uploads/1/3/4/3/134322787/funogo.pdf
- https://uploads.strikinglycdn.com/files/2054202c-0151-40fc-8d01-c497a20c371a/wilokutuzajemexuboginupar.pdf
- https://cdn-cms.f-static.net/uploads/4375087/normal_5f8f8b011deac.pdf
- https://uploads.strikinglycdn.com/files/047eacc5-3eca-4301-a0f6-78db3b0070bf/54522356384.pdf
- https://uploads.strikinglycdn.com/files/132658e1-012a-4071-b1f0-182aa0a16bae/vasexexusiritixikowozox.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- juvikenozenukun.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report