SUSPICIOUS — doxis_bikaxogo_vudelategabaxa.pdf
SUSPICIOUS — doxis_bikaxogo_vudelategabaxa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
b0db80ac3608a50ae14017c1c9847d40e3ef78904a57fda19ebc69f027ad2220 - SHA-1:
3f28d88e42897dbc192f10832624de418df575d6 - MD5:
8b5d18fb240a888dc12c2166d5815dd8 - ssdeep:
768:ngGzpD0pEE+HT/4YxNPF05Ob2R0PkZQqwFLbswBsTXr0hv:gGFopElNt05OjkWqwFLJSTXr0hv - TLSH:
T146318DF320D7EC9C768B6B179DEB11995286D78D6036D6A050887B2CC07CAAC2F11A60 - Submitted as: doxis_bikaxogo_vudelategabaxa.pdf
- File type: pdf · Size: 39807 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=hathor%20material%20pdf, https://cdn-cms.f-static.net/uploads/4366029/normal_5f872703153a4.pdf, https://cdn-cms.f-static.net/uploads/4366302/normal_5f877fba547c4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=hathor%20material%20pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f872703153a4.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f877fba547c4.pdf
- https://cdn-cms.f-static.net/uploads/4368501/normal_5f877e5534758.pdf
- https://uploads.strikinglycdn.com/files/9b174056-4c6f-4ace-9c50-5dbf8226d435/98436710088.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/tunitulo.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/5650151.pdf
- https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/towar.pdf
- https://site-1038905.mozfiles.com/files/1038905/48324458060.pdf
- https://site-1039214.mozfiles.com/files/1039214/sepumadaludalunedajak.pdf
- https://site-1037221.mozfiles.com/files/1037221/boposamidi.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nipomomuka_gisotufeje.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/xewuj.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/likanutavorolebonat.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/fafajaxunej_fifuxosuw_jilapowebemibi_rabadu.pdf
- https://uploads.strikinglycdn.com/files/d3dbd1bb-9f46-43f5-a795-cc830c980a4f/lamejixusigevanamet.pdf
- https://uploads.strikinglycdn.com/files/3a9722e7-3c2b-49db-ab55-5bc54ef506f7/vukiwabivixonata.pdf
- https://uploads.strikinglycdn.com/files/7a662f91-b476-4378-b9f1-3f783775f442/88156469401.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- dutitujazekap.weebly.com
- jatorogerujew.weebly.com
- winomumamo.weebly.com
- site-1038905.mozfiles.com
- site-1039214.mozfiles.com
- site-1037221.mozfiles.com
- jakedekokobara.weebly.com
- bedizegoresupa.weebly.com
- guwomenod.weebly.com
- tavumake.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report