SUSPICIOUS — buxamofezo.pdf
SUSPICIOUS — buxamofezo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9babfab2449e960462d822ea5cd7401f190bc97bbb0ae880b695162988a08b70 - SHA-1:
475620849ac08be0d6abf5d832d984368017b20c - MD5:
ccf847be93b896c082af079134e86798 - ssdeep:
768:ogGzpDvpvbdo1hLOxWfT/JdfK8d09ECkafZBnuUn1vFbobs:lGFbpWiWft5qfZ0U1vlobs - TLSH:
T182328DF75097ED4C3987EF03EEAA2559904A96886137A7A4448C763CC47CAEE7E00960 - Submitted as: buxamofezo.pdf
- File type: pdf · Size: 44217 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=the%20amazing%20spider%20man%202%20full%20game%20a, https://uploads.strikinglycdn.com/files/70579094-aab7-400b-827f-8541c854cd36/boxopiwufuxided.pdf, https://uploads.strikinglycdn.com/files/06e4706d-40d5-45f9-8bbf-b91d5599c0e3/dotut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=the%20amazing%20spider%20man%202%20full%20game%20a
- https://uploads.strikinglycdn.com/files/70579094-aab7-400b-827f-8541c854cd36/boxopiwufuxided.pdf
- https://uploads.strikinglycdn.com/files/06e4706d-40d5-45f9-8bbf-b91d5599c0e3/dotut.pdf
- https://uploads.strikinglycdn.com/files/f068cd77-6114-495c-8460-9ec5e49e2b26/38432085179.pdf
- https://cdn.shopify.com/s/files/1/0435/7105/2703/files/78589612198.pdf
- https://cdn-cms.f-static.net/uploads/4367007/normal_5f874402ba63e.pdf
- https://cdn-cms.f-static.net/uploads/4386335/normal_5f8da5a64e774.pdf
- https://cdn-cms.f-static.net/uploads/4371788/normal_5f8d7edbb64bc.pdf
- https://junoxavod.weebly.com/uploads/1/3/1/3/131384771/2b7f84.pdf
- https://moguvikob.weebly.com/uploads/1/3/0/8/130874292/1815821.pdf
- https://bavejojonosepes.weebly.com/uploads/1/3/1/3/131380601/9865678e0364.pdf
- https://bavejojonosepes.weebly.com/uploads/1/3/1/3/131380601/zuvurakufe.pdf
- https://firerokuk.weebly.com/uploads/1/3/1/1/131164187/7420657.pdf
- https://soxajenukaru.weebly.com/uploads/1/3/0/8/130874283/zokebez_dijupe_demukosorazego.pdf
- https://zalopajozi.weebly.com/uploads/1/3/1/4/131453352/nojufovozoliz.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/daxonoretet.pdf
- https://uploads.strikinglycdn.com/files/4889d4ac-ce37-43ae-acf1-3ce2c8a4d3f9/13726871809.pdf
- https://uploads.strikinglycdn.com/files/7d6bd028-56f5-41f1-be81-5120fbb22c87/59432696224.pdf
- https://uploads.strikinglycdn.com/files/fa10cae5-32dc-47f1-9574-e6e1a36a8286/92969143953.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- junoxavod.weebly.com
- moguvikob.weebly.com
- bavejojonosepes.weebly.com
- firerokuk.weebly.com
- soxajenukaru.weebly.com
- zalopajozi.weebly.com
- xojerajap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report