SUSPICIOUS — vabozemivowimexoji.pdf
SUSPICIOUS — vabozemivowimexoji.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a2795b8f39c4938bbffc21edfb85ba30ce8248160377a31d5e8204fde53990fc - SHA-1:
3290881d7fad23bb9ef37166049e25580222e940 - MD5:
72321d157277f23332bb35901d3ba939 - ssdeep:
768:tgGzpDRpMugH5yQnGb8wZIk+uYe91vTP6MYUJGRMZbhBComH:OGFVpTTIkVYebvTyMY7RSb/IH - TLSH:
T18B328DF70097ED4D7A8A9703A9FB1045558AD38C6136A37058DC7B2DC4BCABDBE11460 - Submitted as: vabozemivowimexoji.pdf
- File type: pdf · Size: 44611 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=stick%20war%20legacy%20parents%20guide, https://uploads.strikinglycdn.com/files/9b8793cf-edcc-4edc-b211-d98dc28212a5/40458538003.pdf, https://uploads.strikinglycdn.com/files/8c30ec1a-1a0e-4c8d-a3f5-0fac2b514683/77569604405.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=stick%20war%20legacy%20parents%20guide
- https://uploads.strikinglycdn.com/files/9b8793cf-edcc-4edc-b211-d98dc28212a5/40458538003.pdf
- https://uploads.strikinglycdn.com/files/8c30ec1a-1a0e-4c8d-a3f5-0fac2b514683/77569604405.pdf
- https://uploads.strikinglycdn.com/files/feb180a2-6288-483d-b504-08a0c22e74c0/46174011756.pdf
- https://uploads.strikinglycdn.com/files/1c50bae3-de76-40bc-82d4-938331f284c1/82817633235.pdf
- https://uploads.strikinglycdn.com/files/1d5c413b-f115-4848-9bd7-2ac9dc4ad55e/vedebikefa.pdf
- https://uploads.strikinglycdn.com/files/33fc62b5-813e-45c2-9d0a-0ee681781258/lawinoseguzawal.pdf
- https://uploads.strikinglycdn.com/files/dc99ed6e-07d9-42a3-be34-47e26fe49a6c/37714219444.pdf
- https://uploads.strikinglycdn.com/files/54449e0a-8631-47be-841c-3377e0de53be/zibabexike.pdf
- https://site-1043088.mozfiles.com/files/1043088/60876305112.pdf
- https://site-1042937.mozfiles.com/files/1042937/30687667152.pdf
- https://site-1036858.mozfiles.com/files/1036858/kunimifileser.pdf
- https://site-1041600.mozfiles.com/files/1041600/detodis.pdf
- https://site-1048557.mozfiles.com/files/1048557/guvogorevinudakugel.pdf
- https://site-1041288.mozfiles.com/files/1041288/37446012793.pdf
- https://site-1040042.mozfiles.com/files/1040042/mazeb.pdf
- https://site-1043126.mozfiles.com/files/1043126/27840521939.pdf
- https://site-1040576.mozfiles.com/files/1040576/dupuvapowaxozafi.pdf
- https://uploads.strikinglycdn.com/files/14618817-6097-44bf-989c-7c2b0df8f6dc/rifowagoku.pdf
- https://uploads.strikinglycdn.com/files/2ff0f586-9c75-4fa3-91b3-3b0ec7f7dfb6/89519372199.pdf
- https://uploads.strikinglycdn.com/files/66d5ea79-19ce-4e69-9536-3aba2a9e1e16/tutulodon.pdf
- https://cdn.shopify.com/s/files/1/0488/0200/5157/files/kenmore_elite_refrigerator_error_code_er_1f.pdf
- https://cdn.shopify.com/s/files/1/0428/1260/4582/files/the_golden_dawn_black_clover.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1043088.mozfiles.com
- site-1042937.mozfiles.com
- site-1036858.mozfiles.com
- site-1041600.mozfiles.com
- site-1048557.mozfiles.com
- site-1041288.mozfiles.com
- site-1040042.mozfiles.com
- site-1043126.mozfiles.com
- site-1040576.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report