SUSPICIOUS — bafebo-lujato-dozoxigufi-fofaxudobisexox.pdf
SUSPICIOUS — bafebo-lujato-dozoxigufi-fofaxudobisexox.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b46f9c5d2a3e8dfac3df1d0dd1fb7caec7bb428107919523ec0a8c8191ea3001 - SHA-1:
f20877cf2376156e1ca4052b2869eb7f4bb3d103 - MD5:
f882e145105c03b65bb48918f9209c3a - ssdeep:
768:tgGzpDgpH548jfSpZghUGGcy5MLADlT7jgHkALMPCQ3MrJQwKXY00Eno1D4A:OGF8pHMZ7OADF8HkAQqQ3Mr2wzD7D4A - TLSH:
T18A326CF300A3DD4D7A8BDB03ADEF2519914DDA896032E764859C2B2DE0786BDBE10950 - Submitted as: bafebo-lujato-dozoxigufi-fofaxudobisexox.pdf
- File type: pdf · Size: 45798 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=plantain%20farming%20in%20nigeria%20pdf, https://site-1038407.mozfiles.com/files/1038407/88908501334.pdf, https://site-1040164.mozfiles.com/files/1040164/28330854900.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=plantain%20farming%20in%20nigeria%20pdf
- https://site-1038407.mozfiles.com/files/1038407/88908501334.pdf
- https://site-1040164.mozfiles.com/files/1040164/28330854900.pdf
- https://site-1042450.mozfiles.com/files/1042450/bogifol.pdf
- https://cdn.shopify.com/s/files/1/0497/1069/4557/files/ribate.pdf
- https://cdn.shopify.com/s/files/1/0484/6927/8881/files/illegalargumentexception_file_contains_a_path_separator_android.pdf
- https://cdn.shopify.com/s/files/1/0434/9712/8088/files/35544764591.pdf
- https://cdn.shopify.com/s/files/1/0483/5753/9989/files/appeal_of_the_cherokee_nation_essay.pdf
- https://cdn.shopify.com/s/files/1/0500/1622/3401/files/27713138717.pdf
- https://uploads.strikinglycdn.com/files/3b37ec02-ed9e-4426-8955-6ba203232212/59097965938.pdf
- https://uploads.strikinglycdn.com/files/d06f2843-402f-4315-b970-920f94ca0678/futinaza.pdf
- https://uploads.strikinglycdn.com/files/bbcf8ccf-ea87-48f8-a9c7-beec2a2556f7/zigidezusedaxixifugewip.pdf
- https://uploads.strikinglycdn.com/files/e931bd91-86ec-45cc-895c-5f10de3d4ff4/44736049866.pdf
- https://uploads.strikinglycdn.com/files/71237e6a-f4e7-402a-96b5-8ec2a2ed1da5/kiwewisuzabeli.pdf
- https://cdn.shopify.com/s/files/1/0431/9268/0611/files/the_scarlet_letter_study_guide_chapters_1-3.pdf
- https://cdn.shopify.com/s/files/1/0436/7309/2246/files/xuvofujomivav.pdf
- https://cdn.shopify.com/s/files/1/0484/7648/7841/files/mcculloch_mc1375_canister_steam_cleaner_with_20_accessories.pdf
- https://cdn.shopify.com/s/files/1/0478/6061/3286/files/boxtops_for_education_submission_form.pdf
- https://cdn.shopify.com/s/files/1/0440/6332/6358/files/wodim.pdf
- https://uploads.strikinglycdn.com/files/6eaf004f-6f1c-439f-8cb1-1d2dbb518be9/pekanudoxuwoboruleker.pdf
- https://uploads.strikinglycdn.com/files/78897ca5-da41-46b6-ae2b-7f71c1a1981e/sekax.pdf
- https://uploads.strikinglycdn.com/files/85f23aa3-42b1-47d0-9594-515726d463f4/77674312554.pdf
- https://uploads.strikinglycdn.com/files/d584b304-ade9-4531-a0f6-629016307b29/ritobojegisit.pdf
- https://uploads.strikinglycdn.com/files/8d0999d9-4c53-461d-ab79-80f34c1b3ab3/54054738239.pdf
- https://uploads.strikinglycdn.com/files/40a88474-7d63-42c8-8ac2-525286ed7aeb/21442503703.pdf
Embedded domains
- cctraff.ru
- site-1038407.mozfiles.com
- site-1040164.mozfiles.com
- site-1042450.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report