SUSPICIOUS — pumikerese_puwigujafajig_kekepazupolemo_xodemuvabep.pdf
SUSPICIOUS — pumikerese_puwigujafajig_kekepazupolemo_xodemuvabep.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
dadf511561c74217581d39ee7e50f75134ad5b0209e35a2f6a469dea6d0a43ca - SHA-1:
67fcd2ff2ff81765f4663a353f9823d535195beb - MD5:
a08f2effb36373573656423fff8be8d7 - ssdeep:
768:xgGzpDCeR9wijUyzPNxstEft/G77Qq318toT5ID7Rlz6+U:CGFOe3VjKL/3WotID7Xz6+U - TLSH:
T199325AF351ABED8C7A87DB036EAA291C5189EB4DA12297A05488773CC4BC27D7F00951 - Submitted as: pumikerese_puwigujafajig_kekepazupolemo_xodemuvabep.pdf
- File type: pdf · Size: 44625 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=bd%20facs%20aria%20ii%20manual, https://cdn-cms.f-static.net/uploads/4374835/normal_5f8eb214e99d8.pdf, https://cdn-cms.f-static.net/uploads/4403938/normal_5f91b39ad2d70.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=bd%20facs%20aria%20ii%20manual
- https://cdn-cms.f-static.net/uploads/4374835/normal_5f8eb214e99d8.pdf
- https://cdn-cms.f-static.net/uploads/4403938/normal_5f91b39ad2d70.pdf
- https://cdn-cms.f-static.net/uploads/4386076/normal_5f9620690a067.pdf
- https://cdn-cms.f-static.net/uploads/4370319/normal_5f8cc9c6e4f3e.pdf
- https://uploads.strikinglycdn.com/files/259d578b-997f-48a6-ba2e-00132516dbd0/kedix.pdf
- https://uploads.strikinglycdn.com/files/5f3d8957-bafa-4cd0-af19-f127732c8f47/tajawijajaribuwuzesi.pdf
- https://uploads.strikinglycdn.com/files/03773b6a-db53-49b9-ae29-9f9a5c910940/21503058569.pdf
- https://uploads.strikinglycdn.com/files/b91f7656-4a00-47c3-a131-d440a10fb947/kong_extreme_size_guide.pdf
- https://uploads.strikinglycdn.com/files/0e3cccc1-2598-4a4d-a4d5-d622e3773536/47697248943.pdf
- https://s3.amazonaws.com/vexeliku/2d_array_in_c_programming_examples.pdf
- https://s3.amazonaws.com/dukajevo/waxorusutomedoxodod.pdf
- https://s3.amazonaws.com/zirojopemup/zepefefugurawibofupifemu.pdf
- https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/xupomorusokawowu.pdf
- https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/a1efc2afeeaf.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/vuxuwanu-giwosofib-begemekofegesu.pdf
- https://zosupexaduj.weebly.com/uploads/1/3/0/7/130738593/getegugo_fotatogi_levinow.pdf
- https://s3.amazonaws.com/zetare/composting_and_biogas_production.pdf
- https://s3.amazonaws.com/dejolavubukugeb/zujupimorati.pdf
- https://s3.amazonaws.com/tuxutedi/a_level_economics_revision_guide.pdf
- https://s3.amazonaws.com/davawina/dugisemesivokozu.pdf
- https://s3.amazonaws.com/fatisake/51708667914.pdf
- https://cdn-cms.f-static.net/uploads/4410432/normal_5f964f90e5548.pdf
- https://cdn-cms.f-static.net/uploads/4369168/normal_5f8dc59414fc7.pdf
- https://cdn-cms.f-static.net/uploads/4383916/normal_5f95f8cf61014.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- gazesomudari.weebly.com
- saxexowiki.weebly.com
- jeponiruwapin.weebly.com
- zosupexaduj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report