SUSPICIOUS — xanovit_vaxixerup.pdf
SUSPICIOUS — xanovit_vaxixerup.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
be4d32ed231fa87ee5498e21d140403114c5f1b5d205ff81ee409885b8138fb2 - SHA-1:
f1b55edce455b1bda6a740fc2734ceb02678f182 - MD5:
e334ab908c69b3e6cae258c1886ec73e - ssdeep:
1536:PGF7pml70nx+tjRw4bC4IocMlEGHWk/yv0Jdc+Rt:+F7pQo+tj1m4+5GH/yudx - TLSH:
T1CC34AEF351A7DD8C7A8BAB836EA60155709AC78931369B6019DC7B3CC47827C3F10960 - Submitted as: xanovit_vaxixerup.pdf
- File type: pdf · Size: 55687 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=cnundt%20shnorhavor%20baremaxtanqner%20hay, https://uploads.strikinglycdn.com/files/ad95afd6-4f7b-425f-a713-cb1f315ac3b0/belikis.pdf, https://uploads.strikinglycdn.com/files/98a4560c-51c9-42a5-86df-fdaf2f7ad1dc/mabajejowelejeton.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=cnundt%20shnorhavor%20baremaxtanqner%20hay
- https://uploads.strikinglycdn.com/files/ad95afd6-4f7b-425f-a713-cb1f315ac3b0/belikis.pdf
- https://uploads.strikinglycdn.com/files/98a4560c-51c9-42a5-86df-fdaf2f7ad1dc/mabajejowelejeton.pdf
- https://uploads.strikinglycdn.com/files/78ea9d07-f3b2-4470-b0a4-0aaf6f2a3635/redezukonisorerisaped.pdf
- https://uploads.strikinglycdn.com/files/c9b22e56-3644-46cd-8adb-6e8b03d55550/nerodutu.pdf
- https://site-1043204.mozfiles.com/files/1043204/jibiwipufoganizedizanikiw.pdf
- https://site-1040354.mozfiles.com/files/1040354/viladukig.pdf
- https://site-1038940.mozfiles.com/files/1038940/42181401723.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f873c4d2b05e.pdf
- https://cdn-cms.f-static.net/uploads/4368245/normal_5f876f48d2ec5.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f86f8f25f5e4.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f871b96b10c9.pdf
- https://cdn-cms.f-static.net/uploads/4366346/normal_5f877700b1b97.pdf
- https://uploads.strikinglycdn.com/files/44d0cc8a-d9ec-4e84-b29a-af5d20f17c70/mekobakokabipajezavofut.pdf
- https://uploads.strikinglycdn.com/files/5fad40bd-04ba-4acc-acc4-37a2b506b1bb/94236414492.pdf
- https://uploads.strikinglycdn.com/files/da61ddcd-ee8f-4995-a950-9e7a0b3dd42b/23092229627.pdf
- https://uploads.strikinglycdn.com/files/5e6149ec-b3d3-47b8-83be-9f181621cd50/vufoxojinivabulak.pdf
- https://site-1038631.mozfiles.com/files/1038631/99740809078.pdf
- https://site-1040427.mozfiles.com/files/1040427/jinimadinokidokobobijug.pdf
- https://site-1036926.mozfiles.com/files/1036926/12821324207.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1043204.mozfiles.com
- site-1040354.mozfiles.com
- site-1038940.mozfiles.com
- cdn-cms.f-static.net
- site-1038631.mozfiles.com
- site-1040427.mozfiles.com
- site-1036926.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report