SUSPICIOUS — dasox_wexutamazuf_zupuvunivasimut_bigadifu.pdf
SUSPICIOUS — dasox_wexutamazuf_zupuvunivasimut_bigadifu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f4e4616abee8b0899e62e1fc54f61ef53bc4d6a7e0eabb182880cb2c5cc9e04b - SHA-1:
7fc7d3b81933d0e30c0074590fe556f08c49abc0 - MD5:
56b1fd8487ab8eb4b097d400b612a618 - ssdeep:
768:mgGzpDaZ6I91pp0sK81FfVsNcTuOk7eyhXhJkHpcIOp:zGFuNpp0MDy2CZ7fLKpcIOp - TLSH:
T13030BEF3502BED8C7B869F07AEEA00592108E68D31379AB455D8777CC4B89ED2F01960 - Submitted as: dasox_wexutamazuf_zupuvunivasimut_bigadifu.pdf
- File type: pdf · Size: 36470 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=water%20cycle%20worksheet%20with%20answer%20key, https://cdn-cms.f-static.net/uploads/4374689/normal_5f89710358703.pdf, https://bidutujube.weebly.com/uploads/1/3/4/4/134403342/jugirexenu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=water%20cycle%20worksheet%20with%20answer%20key
- https://s3.amazonaws.com/leguvefu/senusobogimebegavamamu.pdf
- https://cdn-cms.f-static.net/uploads/4374689/normal_5f89710358703.pdf
- https://bidutujube.weebly.com/uploads/1/3/4/4/134403342/jugirexenu.pdf
- https://mogidudurunupiz.weebly.com/uploads/1/3/2/6/132695636/vuboxomidesuduvej.pdf
- https://romovemesokawaj.weebly.com/uploads/1/3/4/4/134479736/mofazuzukasenar_baxiveza_fulonaw_gebusuxivemetu.pdf
- https://s3.amazonaws.com/bokelur/austin_elementary_school_rankings.pdf
- https://bonunobomatujo.weebly.com/uploads/1/3/4/3/134318799/4973005.pdf
- https://s3.amazonaws.com/wofaxil/encphalopathie_infectieuse.pdf
- https://jirunemopisitex.weebly.com/uploads/1/3/4/3/134332051/9312641.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- bidutujube.weebly.com
- mogidudurunupiz.weebly.com
- romovemesokawaj.weebly.com
- bonunobomatujo.weebly.com
- jirunemopisitex.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report