SUSPICIOUS — nomozesesebuxu.pdf
SUSPICIOUS — nomozesesebuxu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c398be1e43612c6c3b98560e0ea7c6c61ad0dd81373509cb913dc1818c74771e - SHA-1:
d1b6e08fafdc143e26855454f1e031fa8acd6136 - MD5:
6dc7e0d023c8b3141603207d240ef904 - ssdeep:
1536:mGFN5U8pI/SzZPEFNEWQ8kqSfnWfuhkiylW2TF:/FN2LHNB4Muh9yll - TLSH:
T1CB34AEF31097CD8C3BC7AF43A9A611592546D7483262DBA0188CBB2CC87C6BD7F51A91 - Submitted as: nomozesesebuxu.pdf
- File type: pdf · Size: 52715 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=unidades%20decenas%20centenas, https://uploads.strikinglycdn.com/files/8c95d9d6-98a2-41cb-bf6b-bcb6eba816b6/rimojexepepo.pdf, https://cdn.shopify.com/s/files/1/0504/1314/2203/files/pub_17_2020.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=unidades%20decenas%20centenas
- https://uploads.strikinglycdn.com/files/8c95d9d6-98a2-41cb-bf6b-bcb6eba816b6/rimojexepepo.pdf
- https://cdn.shopify.com/s/files/1/0504/1314/2203/files/pub_17_2020.pdf
- https://cdn.shopify.com/s/files/1/0504/5226/7168/files/sovurop.pdf
- https://cdn.shopify.com/s/files/1/0494/1211/2551/files/82590663719.pdf
- https://cdn.shopify.com/s/files/1/0498/6752/2237/files/yalp_store_apk_free_download.pdf
- https://cdn.shopify.com/s/files/1/0500/9545/6413/files/90622160470.pdf
- https://uploads.strikinglycdn.com/files/2db1928e-378a-4d26-9346-a21ca93c548b/56006435046.pdf
- https://uploads.strikinglycdn.com/files/64caf9d4-7e88-4b33-bc1f-84f7f099f694/situmodotabebapexupin.pdf
- https://uploads.strikinglycdn.com/files/62b1ac39-464b-4c30-9a25-852a7b5d3070/rarumu.pdf
- https://cdn.shopify.com/s/files/1/0501/8042/3840/files/continental_airlines_onepass_miles_account.pdf
- https://cdn.shopify.com/s/files/1/0501/5234/1692/files/vsdx_to_converter.pdf
- https://uploads.strikinglycdn.com/files/3352215b-2e23-43bc-942a-e2cb33fa4554/lukoxufibogokevenelumode.pdf
- https://uploads.strikinglycdn.com/files/1269eb83-1f61-48e6-b8b9-190c4b76c6c3/90520014020.pdf
- https://uploads.strikinglycdn.com/files/7367288d-5a1d-44e0-a73e-be9fcffafeac/91945130854.pdf
- https://uploads.strikinglycdn.com/files/783a9a4b-09fe-47a7-a4cd-cfd078124a26/jepoduzux.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report