SUSPICIOUS — xumavefodomagaw_vanogufuwarapo_nopokakakamu.pdf
SUSPICIOUS — xumavefodomagaw_vanogufuwarapo_nopokakakamu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ae72ae7b4f5abd232ea1b135be7de21ed76cb4541c74ea5c838dbe1a4360894e - SHA-1:
8a77eaee9fa8727a0882f13db1cae7ff1fe9a2b5 - MD5:
8f294bfd9ed6adbc0ebc12fde930e1cf - ssdeep:
768:wgGzpD7pPLVOh4nAEnX7H2BG4Gmc1kEkGxaemdXWvGuthnIe:dGFPpDnX7WBG0cWE1Mev3hnIe - TLSH:
T136328CF35093FC4C3A879B03AEAB1199A49AD7CDA13793A0544C376DE07C6ED6E10920 - Submitted as: xumavefodomagaw_vanogufuwarapo_nopokakakamu.pdf
- File type: pdf · Size: 44978 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=wall%20street%20oasis%20behavioral%20interview%20guide%20pdf, https://cdn-cms.f-static.net/uploads/4366965/normal_5f8736018d18a.pdf, https://cdn-cms.f-static.net/uploads/4366042/normal_5f8707d40cb18.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=wall%20street%20oasis%20behavioral%20interview%20guide%20pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8736018d18a.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f8707d40cb18.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f87125f0d848.pdf
- https://uploads.strikinglycdn.com/files/2e66f556-2455-4de2-bebc-8dddff360a43/livibadolodudefifaxowa.pdf
- https://uploads.strikinglycdn.com/files/4e268cbf-34c3-4056-9131-c110e762d76d/wobobazakaxidasadofolafon.pdf
- https://uploads.strikinglycdn.com/files/0fb23319-f7a8-4b82-b0c0-421eebcdb940/9571138487.pdf
- https://uploads.strikinglycdn.com/files/7f1b359f-e89c-42b6-8e08-0900be021b79/raxitilubiburivagexup.pdf
- https://site-1042887.mozfiles.com/files/1042887/sejififegato.pdf
- https://site-1041864.mozfiles.com/files/1041864/morexemenudefasoweki.pdf
- https://site-1039669.mozfiles.com/files/1039669/lifikusodiwimijibig.pdf
- https://uploads.strikinglycdn.com/files/123f4587-237a-407c-8696-7bd78f612db7/72042029551.pdf
- https://uploads.strikinglycdn.com/files/4f7e6573-b09d-4648-9b0b-611e2c8d4404/3028959694.pdf
- https://uploads.strikinglycdn.com/files/c05c47af-b93d-4ff2-860d-820c09388c40/17584515964.pdf
- https://uploads.strikinglycdn.com/files/11969932-4ef3-4148-9252-82459eb09797/90360491472.pdf
- https://uploads.strikinglycdn.com/files/930476f5-12ed-4afb-a082-905e8f25a8a5/pevamosepifamutegilorof.pdf
- https://site-1038970.mozfiles.com/files/1038970/webevemow.pdf
- https://site-1038488.mozfiles.com/files/1038488/wediruxamesirujaranalomez.pdf
- https://site-1037282.mozfiles.com/files/1037282/pakamesuzowaneb.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/jatelu-zukolugaw.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/8911912f5f58fde.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1042887.mozfiles.com
- site-1041864.mozfiles.com
- site-1039669.mozfiles.com
- site-1038970.mozfiles.com
- site-1038488.mozfiles.com
- site-1037282.mozfiles.com
- vuxozajuje.weebly.com
- zesopupejilit.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report