SUSPICIOUS — bitakaka.pdf
SUSPICIOUS — bitakaka.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
247b9e2f6902cf19612e61817615bc13435f20cf2b0a99ff148350f69ae4c056 - SHA-1:
e145ea750a7070cb41335959fa0440da247e6c95 - MD5:
d4cd5d3cb8a02afe7400f4762da09e7e - ssdeep:
768:+gGzpDCpu/eoGkzHgDxtnf81bdi1Ns5l/Hzn8MOw+3M8:7GF+pumtnMpi1NsnnJHqM8 - TLSH:
T1B8317EF30093ED8C7E8FAF03AEAB2459504ED38D613697604498676DD0BCAED7E10651 - Submitted as: bitakaka.pdf
- File type: pdf · Size: 40806 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=wilcoxon%20drum%20book%20pdf, https://uploads.strikinglycdn.com/files/87796ccc-4d80-4105-8a30-437aa8a06c63/kudibelinavuxesunifikiki.pdf, https://uploads.strikinglycdn.com/files/7e281fa8-5e78-4fc0-b2f3-d49486107933/doditela.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=wilcoxon%20drum%20book%20pdf
- https://uploads.strikinglycdn.com/files/87796ccc-4d80-4105-8a30-437aa8a06c63/kudibelinavuxesunifikiki.pdf
- https://uploads.strikinglycdn.com/files/7e281fa8-5e78-4fc0-b2f3-d49486107933/doditela.pdf
- https://uploads.strikinglycdn.com/files/845ef6d3-d8bf-4514-a4d6-0fbed7d3c786/17481962068.pdf
- https://uploads.strikinglycdn.com/files/a9fddb7f-9ac7-4557-8a07-15145169baf2/62483964400.pdf
- https://uploads.strikinglycdn.com/files/dbc801b8-6c67-4f98-bcbb-a978c2f2b8b0/kosiw.pdf
- https://uploads.strikinglycdn.com/files/4193586b-1936-47c7-8495-83c15c739137/37802757199.pdf
- https://uploads.strikinglycdn.com/files/6a9ed4ca-bb3a-4f59-b2ba-1aacc90ca998/vewevivafu.pdf
- https://site-1043406.mozfiles.com/files/1043406/dabubanuxozixuwokafug.pdf
- https://site-1042587.mozfiles.com/files/1042587/karatari.pdf
- https://site-1040263.mozfiles.com/files/1040263/sosusetu.pdf
- https://site-1042554.mozfiles.com/files/1042554/71429229843.pdf
- https://rivisoni.weebly.com/uploads/1/3/0/7/130739016/f71a1c6.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/jogowezokuvaxu.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/10610.pdf
- https://cdn.shopify.com/s/files/1/0478/7978/2566/files/zulirononagupevifezef.pdf
- https://cdn.shopify.com/s/files/1/0432/3947/3314/files/58140971453.pdf
- https://cdn.shopify.com/s/files/1/0482/6968/8994/files/molemujegekidupofu.pdf
- https://cdn.shopify.com/s/files/1/0437/9262/9917/files/city_of_longmont_electric.pdf
- https://uploads.strikinglycdn.com/files/552f159b-3f37-473f-a819-233c7c1b3d73/81077548644.pdf
- https://uploads.strikinglycdn.com/files/e5b9a6dc-2159-4b39-8435-780fea6f50a7/kurudojozatopixopokelupo.pdf
- https://uploads.strikinglycdn.com/files/c22b0315-9a7a-4f7c-8510-7597ead84e8e/37600741045.pdf
- https://uploads.strikinglycdn.com/files/db2af6da-606f-4535-8791-8ffc0b153521/99892111702.pdf
- https://uploads.strikinglycdn.com/files/6cb3afc2-b1a0-429e-b1fd-0d957abd549d/40219263753.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1043406.mozfiles.com
- site-1042587.mozfiles.com
- site-1040263.mozfiles.com
- site-1042554.mozfiles.com
- rivisoni.weebly.com
- fijojonibiw.weebly.com
- zoxuzuxebexot.weebly.com
- jakedekokobara.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report