SUSPICIOUS — nexiratuzeloloxukikemoxu.pdf
SUSPICIOUS — nexiratuzeloloxukikemoxu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
ca7b75bf4084579e9e0a04e92b63bb692010bc89711c6058c32a3368040b383d - SHA-1:
3c64f0436a0d3e0b54fb4fa35113f9721fec8685 - MD5:
0615215bf1121510e0731e675b757097 - ssdeep:
768:HgGzpDDrmgoGxqe/qKIrfswiCAPqU+z8+275FFoUMz4tZsJAIoxHW:AGFfrBIrUwiCHUIu75FFod+ZsqIoxHW - TLSH:
T1CB32B0F351A7EC8C7B856B43EEEB10A1318AC38C612357A448D97A3CD46C67D7E10A60 - Submitted as: nexiratuzeloloxukikemoxu.pdf
- File type: pdf · Size: 46477 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=acne+vulgaris+pdf+2015, https://site-1038572.mozfiles.com/files/1038572/gugojokovevodukum.pdf, https://site-1037260.mozfiles.com/files/1037260/35828289398.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=acne+vulgaris+pdf+2015
- https://site-1038572.mozfiles.com/files/1038572/gugojokovevodukum.pdf
- https://site-1037260.mozfiles.com/files/1037260/35828289398.pdf
- https://site-1038505.mozfiles.com/files/1038505/81184996114.pdf
- https://site-1038360.mozfiles.com/files/1038360/70453767957.pdf
- https://site-1039214.mozfiles.com/files/1039214/20298789623.pdf
- https://site-1039209.mozfiles.com/files/1039209/mebinalinokofiwetugo.pdf
- https://site-1036803.mozfiles.com/files/1036803/55822864860.pdf
- https://uploads.strikinglycdn.com/files/30c5b3a9-526c-4a42-9708-8157a14be3a1/72261765381.pdf
- https://uploads.strikinglycdn.com/files/205d33b3-e31b-4155-91ea-d823c2764467/70740343407.pdf
- https://uploads.strikinglycdn.com/files/598e3a65-7f37-49f3-983f-229e9acba664/juruvawakakotur.pdf
- https://uploads.strikinglycdn.com/files/ecf7a0a1-b38f-42e0-8b8b-f7714c8aeec4/bujubipikumejuwofaf.pdf
- https://uploads.strikinglycdn.com/files/3479fca4-3cb7-4547-8d00-313f81465deb/14297447310.pdf
- http://files.stellarendurance.us/uploads/1/3/1/4/131410094/tududakup-wexitoso-livalulunubor-tamab.pdf
- http://wekim.sabpermaculturegroup.com/uploads/1/3/1/3/131383042/ea824a6a5015a4f.pdf
- http://mikof.psms95x.org/uploads/1/3/1/3/131381067/mazefamaxiwe_vesobeputul_zawejerozoxo_ruvajunozizat.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1038572.mozfiles.com
- site-1037260.mozfiles.com
- site-1038505.mozfiles.com
- site-1038360.mozfiles.com
- site-1039214.mozfiles.com
- site-1039209.mozfiles.com
- site-1036803.mozfiles.com
- uploads.strikinglycdn.com
- files.stellarendurance.us
- wekim.sabpermaculturegroup.com
- mikof.psms95x.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report