SUSPICIOUS — pebunevuxe.pdf
SUSPICIOUS — pebunevuxe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
9d28637ddc3a69405e0ddf594a6ef21352a1f7f9e91a7842c706478775a81e1d - SHA-1:
8a120ffe472ef1aee5f44d014b7112e0f6e93744 - MD5:
975454790cf642711a98a6f60da539fe - ssdeep:
768:EgGzpD6pIsxDFmXfKeZPec4enmtV88Rs16s3UAg+6CbQ3WrGO:xGFWpIsV3k16s3UAgoQ3cGO - TLSH:
T14E2F6DF35467ED8C7AC66B036DFB111A5089D78DA233976149986B3CD0BC6BD3E01821 - Submitted as: pebunevuxe.pdf
- File type: pdf · Size: 34534 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=identify%20main%20clause%20and%20subordinate%20clause%20worksheet, https://cdn.shopify.com/s/files/1/0430/9155/8551/files/13997311333.pdf, https://cdn.shopify.com/s/files/1/0497/8494/6850/files/god_of_war_3_para_psp_android.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=identify%20main%20clause%20and%20subordinate%20clause%20worksheet
- https://s3.amazonaws.com/xabalaru/72707256644.pdf
- https://s3.amazonaws.com/sedimeraxufi/wujugewagaranegizazamitiv.pdf
- https://s3.amazonaws.com/zufaxepixiguxax/65763958654.pdf
- https://cdn.shopify.com/s/files/1/0430/9155/8551/files/13997311333.pdf
- https://cdn.shopify.com/s/files/1/0497/8494/6850/files/god_of_war_3_para_psp_android.pdf
- https://cdn.shopify.com/s/files/1/0432/1270/1854/files/learn_to_fly_idle_unblocked_at_school.pdf
- https://cdn.shopify.com/s/files/1/0266/8937/2329/files/jujuronalakekopepit.pdf
- https://cdn.shopify.com/s/files/1/0268/8240/8644/files/40581941722.pdf
- https://cdn.shopify.com/s/files/1/0441/0530/2168/files/freed_as_told_by_christian_grey_download.pdf
- https://cdn.shopify.com/s/files/1/0484/3710/0694/files/66370339311.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/3856059.pdf
- https://modurofeg.weebly.com/uploads/1/3/4/3/134376635/dae44ee717efc.pdf
- https://jerezuwiwufuken.weebly.com/uploads/1/3/4/3/134355676/kifolig.pdf
- https://pisanofinupu.weebly.com/uploads/1/3/1/4/131437881/bixememofoju.pdf
- https://silepokow.weebly.com/uploads/1/3/4/3/134366863/tifebepevi.pdf
- https://fobewesepujub.weebly.com/uploads/1/3/2/3/132303403/rewajabegigosumu.pdf
- https://nidixinaxob.weebly.com/uploads/1/3/0/7/130739699/rezenamupo.pdf
- https://finazodaxuvoj.weebly.com/uploads/1/3/2/6/132682535/nakakowesitupim.pdf
- https://zeronifoza.weebly.com/uploads/1/3/4/3/134312515/6602802.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- jamuseramomuf.weebly.com
- modurofeg.weebly.com
- jerezuwiwufuken.weebly.com
- pisanofinupu.weebly.com
- silepokow.weebly.com
- fobewesepujub.weebly.com
- nidixinaxob.weebly.com
- finazodaxuvoj.weebly.com
- zeronifoza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report