SUSPICIOUS — gikunovesizaf_najitimewosop_fexok.pdf
SUSPICIOUS — gikunovesizaf_najitimewosop_fexok.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f1be56f97d39006fa14519c96e7ff7d820109ec5de25154ca00b4819f59510ed - SHA-1:
d3256727e7bf2d5ec1352889209ece02ffcf4b1b - MD5:
7da8c3ffc934fadda4a93d22b60090e5 - ssdeep:
768:OPgGzpDGphKw0dtpwbd/s5Gr0HeOlAYX0KSGuRH0wjqdaXrzqi:zGFSphl2WSAXlFJjoSrzqi - TLSH:
T1F0328EF32197ED4C7A83AB1359EF205CA14AD3486132E7A09599772CD4BC7BC7E40921 - Submitted as: gikunovesizaf_najitimewosop_fexok.pdf
- File type: pdf · Size: 43456 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=api%20610%2012th%20edition, https://site-1040620.mozfiles.com/files/1040620/sadunilotadiwosotubobo.pdf, https://site-1038514.mozfiles.com/files/1038514/buzajuxepadakajoditawi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=api%20610%2012th%20edition
- https://site-1040620.mozfiles.com/files/1040620/sadunilotadiwosotubobo.pdf
- https://site-1038514.mozfiles.com/files/1038514/buzajuxepadakajoditawi.pdf
- https://site-1036926.mozfiles.com/files/1036926/98954740305.pdf
- https://site-1036691.mozfiles.com/files/1036691/totupemurapezijotupefero.pdf
- https://site-1037245.mozfiles.com/files/1037245/22658564452.pdf
- https://site-1044010.mozfiles.com/files/1044010/desaberudi.pdf
- https://cdn.shopify.com/s/files/1/0436/7240/4118/files/lesson_4-1_reteach_classifying_triangles.pdf
- https://cdn.shopify.com/s/files/1/0485/2413/2514/files/48668805751.pdf
- https://uploads.strikinglycdn.com/files/1f98b446-9666-45fa-98ba-6d0adb83a6d4/766977493.pdf
- https://uploads.strikinglycdn.com/files/26a0bfe2-15ee-4374-8e1b-2726f83d036f/77259671884.pdf
- https://uploads.strikinglycdn.com/files/e5486789-9832-422a-8bdd-e5a1d452d33a/wijobozoxa.pdf
- https://uploads.strikinglycdn.com/files/aac7776e-f87e-4a88-ab1c-56cf552cfd0b/sofajevugozupol.pdf
- https://uploads.strikinglycdn.com/files/ef2a98a1-8d40-4af2-a68f-096672fc7741/9070818789.pdf
- https://uploads.strikinglycdn.com/files/e564d13a-8218-4f6f-aa7a-6968dbf031a2/kitetaminowoziw.pdf
- https://uploads.strikinglycdn.com/files/17d869e3-ec98-4542-beb7-7a3e4cd3b526/votabozuvipaxelozipim.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/ruxozukozuvazu.pdf
- https://bibeliki.weebly.com/uploads/1/3/0/7/130738572/a308adca0d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1040620.mozfiles.com
- site-1038514.mozfiles.com
- site-1036926.mozfiles.com
- site-1036691.mozfiles.com
- site-1037245.mozfiles.com
- site-1044010.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- jatorogerujew.weebly.com
- bibeliki.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report