SUSPICIOUS — goxefa_nubomonuvetafet_zidukobejaxig_welenipenuz.pdf
SUSPICIOUS — goxefa_nubomonuvetafet_zidukobejaxig_welenipenuz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d83fa9a8ef1ad4bfe98073a7b0eeb36ee88eadd305274b2f2ff48a63447ac900 - SHA-1:
40fe717dc22a88e1aa9f2ccd1462e5c39cb45a24 - MD5:
bcb17191bbf13975de95f7578c1bd525 - ssdeep:
768:RgGzpDXpesuZadZXWh+wAfd6XpHbSwlEYtRTIzff33CrETv:iGFLpv1B4XpHbSwlLRTID6rETv - TLSH:
T166328DF705ABED4CB98B9B03ADEA1165A186C38C6133E7A0448C673D987C1BD7F10961 - Submitted as: goxefa_nubomonuvetafet_zidukobejaxig_welenipenuz.pdf
- File type: pdf · Size: 45341 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=in%20cold%20blood%20persons%20unknown%20study%20guide%20answers, https://uploads.strikinglycdn.com/files/e86d7fb1-c22a-4861-a331-f8bb0ec4470c/dusukuduvo.pdf, https://uploads.strikinglycdn.com/files/dc49ba4d-2785-47ee-be54-89cef961c61e/32185107829.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=in%20cold%20blood%20persons%20unknown%20study%20guide%20answers
- https://uploads.strikinglycdn.com/files/e86d7fb1-c22a-4861-a331-f8bb0ec4470c/dusukuduvo.pdf
- https://uploads.strikinglycdn.com/files/dc49ba4d-2785-47ee-be54-89cef961c61e/32185107829.pdf
- https://uploads.strikinglycdn.com/files/86ba1bc6-a643-4afe-9502-90d2272147e0/28054636939.pdf
- https://uploads.strikinglycdn.com/files/25cfa592-e0c5-4b9a-ad4e-b5bcb22fa620/42678059739.pdf
- https://uploads.strikinglycdn.com/files/86b05caa-f054-4c5e-a9d4-c955afe5cfe9/pejidejelelowerakulexi.pdf
- https://site-1040977.mozfiles.com/files/1040977/vaxoxugupafof.pdf
- https://site-1042593.mozfiles.com/files/1042593/letoboluposazojikilif.pdf
- https://site-1043891.mozfiles.com/files/1043891/lodob.pdf
- https://site-1041491.mozfiles.com/files/1041491/71401509897.pdf
- https://uploads.strikinglycdn.com/files/c476e1fd-4e7e-4b7d-95a7-cba33fdd55b9/zosalulemafeparo.pdf
- https://uploads.strikinglycdn.com/files/2a24feed-dc3c-469b-b883-ba6e03567fcd/75356799806.pdf
- https://uploads.strikinglycdn.com/files/aa7db092-3a54-40d4-bc47-09a46c0b48bc/fegojetefaxoza.pdf
- https://site-1044067.mozfiles.com/files/1044067/69328761669.pdf
- https://site-1038999.mozfiles.com/files/1038999/kapevore.pdf
- https://site-1043328.mozfiles.com/files/1043328/57430670510.pdf
- https://site-1039998.mozfiles.com/files/1039998/46556365181.pdf
- https://site-1039355.mozfiles.com/files/1039355/45972831855.pdf
- https://uploads.strikinglycdn.com/files/9272cc7a-3427-466e-b676-84952e45ae23/91555248680.pdf
- https://uploads.strikinglycdn.com/files/a873adf3-62ac-4db1-b1a2-5e2d21cae0b8/pozurilovanidarag.pdf
- https://uploads.strikinglycdn.com/files/15b71048-7ed7-4e44-97bc-5c70a2da0721/kabewopedexegitu.pdf
- https://uploads.strikinglycdn.com/files/21a031fc-9259-4e63-91fd-8829125b1170/46791134581.pdf
- https://uploads.strikinglycdn.com/files/54586294-ff45-4724-a130-9341ab17253e/33114507754.pdf
- https://site-1041779.mozfiles.com/files/1041779/81737905893.pdf
- https://site-1039667.mozfiles.com/files/1039667/17126363346.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1040977.mozfiles.com
- site-1042593.mozfiles.com
- site-1043891.mozfiles.com
- site-1041491.mozfiles.com
- site-1044067.mozfiles.com
- site-1038999.mozfiles.com
- site-1043328.mozfiles.com
- site-1039998.mozfiles.com
- site-1039355.mozfiles.com
- site-1041779.mozfiles.com
- site-1039667.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report