SUSPICIOUS — vulofulikodazovegivi.pdf
SUSPICIOUS — vulofulikodazovegivi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
db12e684745af351c8c241f3233d365062f22e4ebaadb2bdd68c48b17f83ea58 - SHA-1:
c6e0558dcb04dda84c4ec22667756df725501911 - MD5:
6c277439e7b950f5897d371be2b19d95 - ssdeep:
768:BgGzpDKzr2dtlzYQ8At/b1Lz8f5VbKS5Rt58RPGuc8Cf2Kb1tJ4/FH:yGF+nd+tz5g5P5Rz8RqNeKb1r4/FH - TLSH:
T17C329DF310ABDD4C7986EB135DB72458644AC78C7132A7A44AC97B2D847C2BD5E10EA0 - Submitted as: vulofulikodazovegivi.pdf
- File type: pdf · Size: 47432 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=ixpand+update+tool+for+windows+pc, https://uploads.strikinglycdn.com/files/245bc40f-edc5-4a42-bd84-e3440d7eab5a/86455176161.pdf, https://uploads.strikinglycdn.com/files/27f90e96-7efa-46c3-8f8c-d68364cd59bf/43816476287.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=ixpand+update+tool+for+windows+pc
- https://uploads.strikinglycdn.com/files/245bc40f-edc5-4a42-bd84-e3440d7eab5a/86455176161.pdf
- https://uploads.strikinglycdn.com/files/27f90e96-7efa-46c3-8f8c-d68364cd59bf/43816476287.pdf
- https://uploads.strikinglycdn.com/files/6ab579a1-2f6d-4b84-86e5-1bcffdcd0621/satutuxuwuf.pdf
- https://uploads.strikinglycdn.com/files/ff2c6a55-569e-40f9-9282-a1a1e2045581/kuzokozenupupuwen.pdf
- https://uploads.strikinglycdn.com/files/43c96c22-e8a4-4df3-84fc-46bb210fbebd/dazubebetumenugubugawep.pdf
- https://uploads.strikinglycdn.com/files/c0e24b0a-4bf2-40bf-afd7-ecd33c0dd733/17878028156.pdf
- https://site-1037071.mozfiles.com/files/1037071/mivebosizuwaxizafinototu.pdf
- https://site-1036868.mozfiles.com/files/1036868/8483918915.pdf
- https://site-1039621.mozfiles.com/files/1039621/27561634362.pdf
- https://site-1041782.mozfiles.com/files/1041782/96760653834.pdf
- http://jonezo.tulatu.co.za/uploads/1/3/2/6/132681443/3952844.pdf
- http://tebefedo.al-anon-sc.org/uploads/1/3/0/7/130739564/gexulubuvife_vejurademomikob_buvagutenavo.pdf
- http://wirufex.debracoxx.com/uploads/1/3/1/4/131437092/sopazonedolog-mosigatime-nufaxajejamimu-balub.pdf
- http://xepuwevo.noelsylvester.com/uploads/1/3/1/3/131397997/6668793.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1037071.mozfiles.com
- site-1036868.mozfiles.com
- site-1039621.mozfiles.com
- site-1041782.mozfiles.com
- jonezo.tulatu.co.za
- tebefedo.al-anon-sc.org
- wirufex.debracoxx.com
- xepuwevo.noelsylvester.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report