SUSPICIOUS — juwasuvutuxejaf-nutumefagemilak-voduvivotu-robiledajolaw.pdf
SUSPICIOUS — juwasuvutuxejaf-nutumefagemilak-voduvivotu-robiledajolaw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
dc1b06796afc8c9bc648a3da96d80594629588c4f87c162ca05281935de22861 - SHA-1:
4c11e4bd8b9333ce9ed440b9e869dc020f9e2004 - MD5:
60c09eb72f45cee978efa9ca4129d831 - ssdeep:
768:MgGzpDpecM+hZklq6F3SQ3dALSWJ2N4VFeVClQihGczFsz89g1T/pLP:JGF9ecDh1cmLSkve0QihGgXgJpLP - TLSH:
T14E328DF71097ED8CBA879B03ADB71155248EC38C6236A7A0158CBB2D85BC5BC7F10961 - Submitted as: juwasuvutuxejaf-nutumefagemilak-voduvivotu-robiledajolaw.pdf
- File type: pdf · Size: 44377 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=farmacologia%20humana%20florez%206%20edicion%20mega, https://uploads.strikinglycdn.com/files/f4c75153-8847-4e29-9e71-17570ed91563/wisiwegitonenidor.pdf, https://uploads.strikinglycdn.com/files/7c3dd82c-19a5-493a-bbca-a0968e73d8f4/1158478234.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=farmacologia%20humana%20florez%206%20edicion%20mega
- https://uploads.strikinglycdn.com/files/f4c75153-8847-4e29-9e71-17570ed91563/wisiwegitonenidor.pdf
- https://uploads.strikinglycdn.com/files/7c3dd82c-19a5-493a-bbca-a0968e73d8f4/1158478234.pdf
- https://uploads.strikinglycdn.com/files/f4868bc4-f3ed-4342-b0b6-2073c2aa944f/tifidu.pdf
- https://uploads.strikinglycdn.com/files/e1f9b115-59eb-46ae-a4c9-38fcc46ca620/bexesojikumewap.pdf
- https://uploads.strikinglycdn.com/files/bafbfe35-bc68-4afd-89f1-5bbddc7c1353/93161363990.pdf
- https://uploads.strikinglycdn.com/files/83ac7b3d-c5d1-45b9-b052-3b635204de90/bifemimafopobanat.pdf
- https://uploads.strikinglycdn.com/files/73f6d571-5639-4648-bfef-5313d3ba208e/20710657667.pdf
- https://uploads.strikinglycdn.com/files/a700139c-602f-4dcd-94c7-1a39d8b46972/45116030185.pdf
- https://uploads.strikinglycdn.com/files/16104d9e-6671-4996-b1eb-f1f56bfd53c9/31840610776.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f86fc3c802af.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f870e49e7d93.pdf
- https://uploads.strikinglycdn.com/files/86525453-63b3-41d3-9a22-b135da2afbfd/jinuzeraxuved.pdf
- https://uploads.strikinglycdn.com/files/350b2205-ca61-4dc4-8681-75f872723510/mawerufifusurovevimijawu.pdf
- https://uploads.strikinglycdn.com/files/56da929a-73e0-4d97-8694-bfda532ddd1d/52022632373.pdf
- https://uploads.strikinglycdn.com/files/590a6fe9-0a74-421f-8e8a-890900be72cb/voburafu.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f87140928529.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f8721f7ae6ed.pdf
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f870dceb6b37.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f872a876dd97.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f8729f78f10d.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rugatu-rugot.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/5e7030064.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/1286989.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kirorafagosox.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- vuxozajuje.weebly.com
- boguvetasitob.weebly.com
- jawowigo.weebly.com
- gimejexoxixaza.weebly.com
- genigudepa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report