SUSPICIOUS — xuxawawodasufabizumow.pdf
SUSPICIOUS — xuxawawodasufabizumow.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
c9e3e90d03680aef007dab138e2dab8f87fa9a4f983fca05d16d19df4590bc74 - SHA-1:
a7d28155a217a67a519837000c84e857f323aeba - MD5:
408c3d84a10e59bd0599ae87b6fa9a34 - ssdeep:
768:zgGzpDZSk6O4NgzZTV4q3K3OIb+0r5hsQOE8KbN0Tb62fvGN2:MGF9F4SzZ5iO704Q/8KbNWfvGN2 - TLSH:
T181328DF70067ED8C3A8F6B43ADBB0598618AC74D6232929404DDB72DC5B86FDAF00951 - Submitted as: xuxawawodasufabizumow.pdf
- File type: pdf · Size: 46013 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=ejercicios+leyes+gases+3+eso+pdf, https://site-1036761.mozfiles.com/files/1036761/tademifazelegiji.pdf, https://site-1038490.mozfiles.com/files/1038490/fufitagivulejimipuwiwag.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=ejercicios+leyes+gases+3+eso+pdf
- https://site-1036761.mozfiles.com/files/1036761/tademifazelegiji.pdf
- https://site-1038490.mozfiles.com/files/1038490/fufitagivulejimipuwiwag.pdf
- https://site-1039446.mozfiles.com/files/1039446/56126118662.pdf
- https://site-1037121.mozfiles.com/files/1037121/zugakegogepomabokef.pdf
- http://files.coloradopricklypawshedgehogs.com/uploads/1/3/0/7/130775838/be47ead.pdf
- http://files.lorettolink.org/uploads/1/3/1/4/131409794/lisedeza-futakebomevan.pdf
- http://xumawaje.artfromalice.com/uploads/1/3/2/6/132696194/dunigabojunelode.pdf
- http://gejafo.newportnewslinks.org/uploads/1/3/1/6/131606140/lemowuzisojul-wutaraji-dizupezude.pdf
- http://xadiguvum.nikonmalta.com/uploads/1/3/1/3/131384240/dukirisoxodunuwo.pdf
- https://uploads.strikinglycdn.com/files/8fe14654-ac3e-433d-ac0f-b02bfadd7cd0/10293710087.pdf
- https://uploads.strikinglycdn.com/files/266664f2-e70c-4fc6-ab5e-57b989682c1e/dasuwizapubipabaxozovegu.pdf
- https://uploads.strikinglycdn.com/files/f43d153d-ef65-4820-a8f1-d578a9bc6260/vavixadujadavuxowog.pdf
- https://uploads.strikinglycdn.com/files/839885ab-2050-4e0c-954b-7f8603ebf5e2/damejum.pdf
- https://uploads.strikinglycdn.com/files/182a5623-7b64-4845-901f-8056a34e6975/vezagamutobobavik.pdf
- https://uploads.strikinglycdn.com/files/618c0184-ab9b-42ca-9d5d-690779390faa/97674454679.pdf
- https://uploads.strikinglycdn.com/files/ed1d25c5-235b-4312-88b0-e49e7fc2533f/13596450342.pdf
- https://uploads.strikinglycdn.com/files/108159aa-ea7c-4b29-877b-fa00b2065ffb/60365605977.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036761.mozfiles.com
- site-1038490.mozfiles.com
- site-1039446.mozfiles.com
- site-1037121.mozfiles.com
- files.coloradopricklypawshedgehogs.com
- files.lorettolink.org
- xumawaje.artfromalice.com
- gejafo.newportnewslinks.org
- xadiguvum.nikonmalta.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report