SUSPICIOUS — xifeves.pdf
SUSPICIOUS — xifeves.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
35ff3dc40d4377a8dc057fe45db42509c584e8530b9abdbd83a3761cd2a4a53c - SHA-1:
6a2fd9e783a5dd9ddd8c3ccc552b66f208f1eddb - MD5:
c6e3043406518dfaba9511bfc2740322 - ssdeep:
768:MgGzpDfeZME74hRXSpXgvOTKINXAqRkJc/0hrzK7kHwF14M5PtjFFp1nVYOPFNXV:JGFreZMnwn4M5VjfvVYOdNXsSZZ - TLSH:
T1AA339DF350ABED4C7AC7AB13A9FA2166504DC78C7136E65049486B3CE47C2BDBE10920 - Submitted as: xifeves.pdf
- File type: pdf · Size: 51099 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=dbms%205%20marks%20questions%20with%20answers%20pdf, https://cdn-cms.f-static.net/uploads/4375507/normal_5f91d11f4204d.pdf, https://cdn-cms.f-static.net/uploads/4366042/normal_5f87d6400abb2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=dbms%205%20marks%20questions%20with%20answers%20pdf
- https://cdn-cms.f-static.net/uploads/4375507/normal_5f91d11f4204d.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f87d6400abb2.pdf
- https://cdn-cms.f-static.net/uploads/4380701/normal_5f8bf84ee95f0.pdf
- https://uploads.strikinglycdn.com/files/bbe8fe32-e730-4cf4-a1be-748932e6f213/80395092241.pdf
- https://uploads.strikinglycdn.com/files/f01b66f5-6a5e-45c9-ab51-24b6143041ba/mizipikaxivebigotemetin.pdf
- https://uploads.strikinglycdn.com/files/ce23f9cf-2a41-4506-8f32-1bf59a51065e/80106352617.pdf
- https://uploads.strikinglycdn.com/files/77c292d3-afe0-42e1-90ca-28984fb391a4/29438496340.pdf
- https://uploads.strikinglycdn.com/files/a9d3c998-8a33-4b53-8b94-63b445ac04ec/wapegetiserovumisi.pdf
- https://cdn-cms.f-static.net/uploads/4384048/normal_5f8f78c0ca995.pdf
- https://cdn-cms.f-static.net/uploads/4369332/normal_5f87bfb47538c.pdf
- https://cdn-cms.f-static.net/uploads/4370056/normal_5f8821eabe922.pdf
- https://cdn.shopify.com/s/files/1/0497/4893/4819/files/rca_universal_remote_control_programming_instructions.pdf
- https://cdn.shopify.com/s/files/1/0433/1854/2504/files/95935372544.pdf
- https://cdn.shopify.com/s/files/1/0500/2651/2544/files/kiwijiz.pdf
- https://cdn.shopify.com/s/files/1/0433/7808/1959/files/specially_designed_instruction_for_executive_functioning.pdf
- https://cdn.shopify.com/s/files/1/0496/4902/5188/files/area_code_705_canada.pdf
- https://cdn.shopify.com/s/files/1/0483/7782/3385/files/best_nazi_zombies_songs.pdf
- https://cdn.shopify.com/s/files/1/0432/9567/0427/files/aprilaire_thermostat_8463_installation_manual.pdf
- https://cdn.shopify.com/s/files/1/0483/0520/9499/files/proton_bus_simulator_beta_apk_obb.pdf
- https://cdn.shopify.com/s/files/1/0431/0987/5873/files/sandy_alcantara_fangraphs.pdf
- https://cdn.shopify.com/s/files/1/0483/0376/7713/files/printable_guitar_bar_chords_chart.pdf
- https://cdn.shopify.com/s/files/1/0463/3319/8498/files/cool_earrings_for_men.pdf
- https://cdn.shopify.com/s/files/1/0483/4328/5923/files/zujobaw.pdf
- https://cdn.shopify.com/s/files/1/0268/7493/7532/files/juegos_game_boy_advance_android_mario_kart.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report