SUSPICIOUS — labat_xavabubufe_wivepipak_joriruviju.pdf
SUSPICIOUS — labat_xavabubufe_wivepipak_joriruviju.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
cb0a466790483c67982072a69c5af4f1f5d3197460e1adfdde2dac8289d8cd7b - SHA-1:
5e92bfbb95016fff49544d7c6630a9972fd222a6 - MD5:
4c21a53253b585be259452798974b451 - ssdeep:
768:QgGzpDQpZCgVBFOowERjrGaaO5F9R8rWcKyvlIrTyWCokgYFUtNJzzd4P:9GFkpZPLht/KrW9Y6yW+FUH/d4P - TLSH:
T15B317BF30497EC4CBA8BA703ADAB166A60C9C34D6127E7A0558C676CD4BC5BD3F00961 - Submitted as: labat_xavabubufe_wivepipak_joriruviju.pdf
- File type: pdf · Size: 42150 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=jbl%20flip%203%20app, https://uploads.strikinglycdn.com/files/32127526-66a8-42c1-96b4-2c5a38875bea/18226324411.pdf, https://uploads.strikinglycdn.com/files/2e1a6c4b-be45-46e9-8cbe-8c682c58d67a/85881729051.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=jbl%20flip%203%20app
- https://uploads.strikinglycdn.com/files/32127526-66a8-42c1-96b4-2c5a38875bea/18226324411.pdf
- https://uploads.strikinglycdn.com/files/2e1a6c4b-be45-46e9-8cbe-8c682c58d67a/85881729051.pdf
- https://uploads.strikinglycdn.com/files/14566c6d-a010-427a-8314-ca833503b722/36933113338.pdf
- https://uploads.strikinglycdn.com/files/39dfe45a-b656-40e6-a0f3-5db5e52eb671/nofok.pdf
- https://site-1038887.mozfiles.com/files/1038887/fokalenitevo.pdf
- https://site-1039289.mozfiles.com/files/1039289/zubepinobigot.pdf
- https://uploads.strikinglycdn.com/files/285712c2-3f4b-4bb8-91af-db1c44f9c82a/jijezariniboridemas.pdf
- https://uploads.strikinglycdn.com/files/a33244c3-88b9-43f1-b026-b991c6cb318f/37825467119.pdf
- https://uploads.strikinglycdn.com/files/27522de3-de9d-4dc0-bc60-5fb33c7e2da6/difamaxidugiziwep.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/4323774.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/b55817.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/dekefomivupe-kovak-talajonipa-fedebiraroz.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/raxefiko-winukiwoxuvi-bigaga-jepininuvasono.pdf
- https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/bamukumixuv.pdf
- https://cdn.shopify.com/s/files/1/0484/3012/1112/files/clone_app_android_xda.pdf
- https://cdn.shopify.com/s/files/1/0482/8361/5394/files/sabc_sport_tv_guide_tomorrow.pdf
- https://cdn.shopify.com/s/files/1/0479/5505/0652/files/32874164394.pdf
- https://cdn.shopify.com/s/files/1/0266/7836/2298/files/43925549555.pdf
- https://cdn.shopify.com/s/files/1/0440/7413/9813/files/delirium_free_online_book.pdf
- https://site-1038779.mozfiles.com/files/1038779/36983298931.pdf
- https://site-1043791.mozfiles.com/files/1043791/42092176867.pdf
- https://site-1036667.mozfiles.com/files/1036667/zobakaxexeretelet.pdf
- https://site-1042931.mozfiles.com/files/1042931/63020561233.pdf
- https://site-1036633.mozfiles.com/files/1036633/65767952848.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1038887.mozfiles.com
- site-1039289.mozfiles.com
- wepugimi.weebly.com
- jaserasozupog.weebly.com
- zoxuzuxebexot.weebly.com
- xebikazogede.weebly.com
- mogezisatizate.weebly.com
- cdn.shopify.com
- site-1038779.mozfiles.com
- site-1043791.mozfiles.com
- site-1036667.mozfiles.com
- site-1042931.mozfiles.com
- site-1036633.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report