SUSPICIOUS — navoxuxi.pdf
SUSPICIOUS — navoxuxi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b5066ddea609aa2b7f69b5d3ce7cc7114449c4f7cff6d76bbf3e1048cfd4fe21 - SHA-1:
24d917b4b0d19629b45eb60fd952a85d1ee696af - MD5:
eb3a7a2bfbfa4e5dc562eeeeaaa7918c - ssdeep:
768:QgGzpDqCP+umio8VDsT5mD254tS8zXO7qTINdAa+A5AiV:9GF2Cw5mxtJz6rAa+A5AiV - TLSH:
T16A306BF351ABDD8C3687DB0369EA2189518AD34C2072EB649598777CC47C3BD2E10E60 - Submitted as: navoxuxi.pdf
- File type: pdf · Size: 37183 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=beginner+guitar+pieces+pdf, https://uploads.strikinglycdn.com/files/7c02fca7-8cd9-49e2-ae57-696742ec3261/zinepesuwegudazomurusede.pdf, https://uploads.strikinglycdn.com/files/2f138428-b689-49fd-82c7-c1362a750927/36161440484.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=beginner+guitar+pieces+pdf
- https://uploads.strikinglycdn.com/files/7c02fca7-8cd9-49e2-ae57-696742ec3261/zinepesuwegudazomurusede.pdf
- https://uploads.strikinglycdn.com/files/2f138428-b689-49fd-82c7-c1362a750927/36161440484.pdf
- https://uploads.strikinglycdn.com/files/2c11104c-319e-477e-867c-b1cb4cd1d7e3/19624571428.pdf
- https://site-1037156.mozfiles.com/files/1037156/40252496953.pdf
- https://site-1036852.mozfiles.com/files/1036852/xevofemufefopixaterisugi.pdf
- https://cdn.shopify.com/s/files/1/0428/6539/3831/files/zorowabatakexerobizele.pdf
- https://cdn.shopify.com/s/files/1/0440/7672/8485/files/return_man_3_unblocked_at_school_66.pdf
- https://cdn.shopify.com/s/files/1/0481/7898/7165/files/34297301294.pdf
- https://cdn.shopify.com/s/files/1/0427/8878/2236/files/27635133173.pdf
- https://cdn.shopify.com/s/files/1/0477/0136/0806/files/sony_dream_machine_time_set_icf-c318.pdf
- https://uploads.strikinglycdn.com/files/f6efa9ce-9909-426e-9f6b-fb35d39a8d0d/66322661016.pdf
- https://uploads.strikinglycdn.com/files/f7d6840d-aa19-4bdc-be0a-3afe8e599f0c/tefulubuwamofava.pdf
- https://uploads.strikinglycdn.com/files/285079fc-0f56-4221-a2f0-c0d82aef646d/90921544813.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1037156.mozfiles.com
- site-1036852.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report