SUSPICIOUS — xupabozividefirupax.pdf
SUSPICIOUS — xupabozividefirupax.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d530f4d6a01cd9aa69978fee77f5654b3f89999123f723c8c608081ae0a9b913 - SHA-1:
6e3c39c911fc92556bc1537ca5bbfa48bd14e5c9 - MD5:
ab4ae82abd52133ff5f39539e6ea9137 - ssdeep:
768:KgGzpD1p+yySRZgTKI9k9o4ITgMTSxKjqctDeZ5Du3hwpcScFvP1PJ5v06wjA7tA:XGFJpkTt4IEMTScjavJcFX1xF0pZ/olg - TLSH:
T1C6338DF31073ED4CB68F9B43AEBA0509654DD68C6036AB9055482B6DC47CAFE7F00A91 - Submitted as: xupabozividefirupax.pdf
- File type: pdf · Size: 48257 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=manifestacion%20de%20la%20voluntad%20expresa%20y%20tacita, https://cdn-cms.f-static.net/uploads/4366034/normal_5f87014770dc6.pdf, https://cdn-cms.f-static.net/uploads/4365541/normal_5f871dcf948b8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=manifestacion%20de%20la%20voluntad%20expresa%20y%20tacita
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f87014770dc6.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f871dcf948b8.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f86fa6362cfb.pdf
- https://uploads.strikinglycdn.com/files/3df375d6-06b8-4599-88cd-3ec948dd695b/jokasixikirokonefuno.pdf
- https://uploads.strikinglycdn.com/files/3e61b8dc-cdb7-45dc-8fb3-3ce8bf049003/metunepakos.pdf
- https://uploads.strikinglycdn.com/files/77740454-22a4-4122-b2be-42a31e0c466c/zafelamuwefuzeboru.pdf
- https://uploads.strikinglycdn.com/files/8d11b7bc-72a0-49ff-bdab-232523335b96/zijujig.pdf
- https://uploads.strikinglycdn.com/files/c3fe4245-71dd-48a6-a30b-07d23145d4a2/19603015711.pdf
- https://uploads.strikinglycdn.com/files/e4c58073-9323-4dc5-bf49-b9b2a400f02a/29504077941.pdf
- https://uploads.strikinglycdn.com/files/699495ec-016f-4b89-a6ca-d8e7ffc186d7/12614500684.pdf
- https://uploads.strikinglycdn.com/files/0b1f9d19-e2c3-401a-9397-89cf091a79ca/xebidamukinepenanupe.pdf
- https://uploads.strikinglycdn.com/files/91761ba8-bf59-4177-9a4c-5daef2fb3ac9/58289361796.pdf
- https://cdn.shopify.com/s/files/1/0494/1817/4631/files/maths_practice_worksheets_for_class_10_cbse.pdf
- https://cdn.shopify.com/s/files/1/0498/4930/3202/files/vuvub.pdf
- https://cdn.shopify.com/s/files/1/0501/6928/2725/files/nokejimederenosapaz.pdf
- https://cdn.shopify.com/s/files/1/0440/8085/7253/files/xafewi.pdf
- https://site-1043353.mozfiles.com/files/1043353/7791532212.pdf
- https://site-1044076.mozfiles.com/files/1044076/87242657881.pdf
- https://site-1038605.mozfiles.com/files/1038605/gagop.pdf
- https://site-1038608.mozfiles.com/files/1038608/sizuv.pdf
- https://cdn.shopify.com/s/files/1/0468/8750/1981/files/filter_queen_majestic_replacement_hose.pdf
- https://cdn.shopify.com/s/files/1/0439/1128/2843/files/14764101713.pdf
- https://cdn.shopify.com/s/files/1/0437/8938/5890/files/super_mario_bros_the_lost_levels_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0433/5638/9528/files/tranont_compensation_plan_2020.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1043353.mozfiles.com
- site-1044076.mozfiles.com
- site-1038605.mozfiles.com
- site-1038608.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report