SUSPICIOUS — bepabexobu_xodoxavu_lenusigobu_xadutedid.pdf
SUSPICIOUS — bepabexobu_xodoxavu_lenusigobu_xadutedid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f9ba563f95af438ee133671dd346735e20072f72dfa6e121b938a0840c5a418f - SHA-1:
3895df5628169fb682b2ff21227a51ea509d01e0 - MD5:
118b76c1ded5d714a7acc28eba794a23 - ssdeep:
1536:jGFzpZzl9UCBgbbNaSCk/4G1WaNkf8Fj7KOPoD/bqV+:yFzpZnTBANaK/4GAaNkf8FfKOPobbB - TLSH:
T1A636C0F75097FD8C27966F0799B7146DA18ACB89613356E008C87A2CC5BCAFC6F10611 - Submitted as: bepabexobu_xodoxavu_lenusigobu_xadutedid.pdf
- File type: pdf · Size: 67974 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=left%204%20dead%202%20admin%20system, https://uploads.strikinglycdn.com/files/3f9e3f51-11b5-4e8f-be3b-54b687ace3e8/powapesebijuxazuxoxibik.pdf, https://uploads.strikinglycdn.com/files/e53fe6d5-9600-4817-bb45-6f6e05266856/lokibogidekupa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=left%204%20dead%202%20admin%20system
- https://uploads.strikinglycdn.com/files/3f9e3f51-11b5-4e8f-be3b-54b687ace3e8/powapesebijuxazuxoxibik.pdf
- https://uploads.strikinglycdn.com/files/e53fe6d5-9600-4817-bb45-6f6e05266856/lokibogidekupa.pdf
- https://uploads.strikinglycdn.com/files/1c7f2611-f5d0-49c0-9e77-dde51b6cce5c/9999545507.pdf
- https://uploads.strikinglycdn.com/files/61d29ea4-3814-4ab8-a4a6-cfbb3b73fba0/wewatupewubanisurid.pdf
- https://uploads.strikinglycdn.com/files/c9a03bd6-898a-4d26-b730-ae22f04ebf45/rokuv.pdf
- https://site-1041173.mozfiles.com/files/1041173/21841604370.pdf
- https://site-1038770.mozfiles.com/files/1038770/1610467198.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/nesubine.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/kokobobe_bogaxusesewisel.pdf
- https://uploads.strikinglycdn.com/files/f54e97f2-7256-4f1a-b9cc-cd1f8b79adba/nimunibekumunudewaw.pdf
- https://uploads.strikinglycdn.com/files/bbf869d4-50ce-47c5-b56b-f2fd65fce4ac/rutisiximi.pdf
- https://uploads.strikinglycdn.com/files/2bddcc58-6f01-4a72-bc70-2c37ef2ca9f8/22563460943.pdf
- https://uploads.strikinglycdn.com/files/98cebb1a-67f1-4e37-8d81-d0e71d815e2e/49054610452.pdf
- https://uploads.strikinglycdn.com/files/592171db-ff64-491f-b619-a6cc6b91b753/92475536406.pdf
- https://uploads.strikinglycdn.com/files/3c77f445-5cea-464f-b6a1-6e15f7adff17/84332105465.pdf
- https://site-1040506.mozfiles.com/files/1040506/toboledavepupafelazo.pdf
- https://site-1040988.mozfiles.com/files/1040988/93196097510.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1041173.mozfiles.com
- site-1038770.mozfiles.com
- gimejexoxixaza.weebly.com
- walijogopabo.weebly.com
- site-1040506.mozfiles.com
- site-1040988.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report