SUSPICIOUS — xusasepivaf_tejerilidibus_kilefojofuvewon_wejufuwupul.pdf
SUSPICIOUS — xusasepivaf_tejerilidibus_kilefojofuvewon_wejufuwupul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
9983955d890d2611a8649a5fc368fddddcc9dc04707e3707df948c4c30e83e86 - SHA-1:
d310d3c6a99f7e71ac71df1f14e81e12796fdd36 - MD5:
e1517a4704b8c830d1a8aa196b1db61c - ssdeep:
768:WgGzpDTp+S1HmsVrmGyL5zsMXT8z4UnL4pK68lpfTFBBcI5/aZhQSjFH:DGFvp+VTsL4YBXc2fSjFH - TLSH:
T18133AFF35097ED4C2E876F936DAB25586589C3897236A76404CCB76DC0BC2BD6F10820 - Submitted as: xusasepivaf_tejerilidibus_kilefojofuvewon_wejufuwupul.pdf
- File type: pdf · Size: 48210 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=tipos%20de%20archivos%20de%20imagenes, https://cdn-cms.f-static.net/uploads/4365606/normal_5f8721ca4b952.pdf, https://cdn-cms.f-static.net/uploads/4366050/normal_5f870bceee975.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=tipos%20de%20archivos%20de%20imagenes
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f8721ca4b952.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f870bceee975.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f873edf530b0.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f86fed5b3038.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f8753113811e.pdf
- https://site-1042555.mozfiles.com/files/1042555/fekum.pdf
- https://site-1040574.mozfiles.com/files/1040574/17024539843.pdf
- https://site-1039893.mozfiles.com/files/1039893/85535553841.pdf
- https://uploads.strikinglycdn.com/files/13d055b4-017c-41e5-9781-1ed59d615fc0/xafetolomubixajoxoleluruf.pdf
- https://uploads.strikinglycdn.com/files/cc97acf8-3a90-4cdc-a7a9-a06badc53619/liratesoboragufiti.pdf
- https://uploads.strikinglycdn.com/files/1a1c1071-64b3-4248-a6dd-9afce40a4a50/62622882594.pdf
- https://uploads.strikinglycdn.com/files/a035d258-ce32-4a4a-988d-768cd0def8e1/kakekasasomurotapowab.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/1559686.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/837046.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/8471045.pdf
- https://cdn.shopify.com/s/files/1/0486/3157/8782/files/lunirevukuwusi.pdf
- https://cdn.shopify.com/s/files/1/0481/6322/5767/files/5657496784.pdf
- https://cdn.shopify.com/s/files/1/0437/6982/3390/files/3626823507.pdf
- https://cdn.shopify.com/s/files/1/0430/9227/9460/files/watch_shingeki_no_kyojin_season_3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1042555.mozfiles.com
- site-1040574.mozfiles.com
- site-1039893.mozfiles.com
- uploads.strikinglycdn.com
- lodirunesu.weebly.com
- bedizegoresupa.weebly.com
- gusumadanu.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report