SUSPICIOUS — matebulixeja.pdf
SUSPICIOUS — matebulixeja.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
37ac47131804af4406e78d8884b249275e1bd3ad3b17b539536b41906da747a4 - SHA-1:
142e72fc02d5807b04bf650d3b6fc228432d7098 - MD5:
09cc94b0eb6e63a0175ed18f898188b9 - ssdeep:
768:ugGzpDwXZJRuZ4jYaQpseb7spcHQ+GBo8mAl1yWsw:LGFUXlkkdBoLgEWsw - TLSH:
T1A02F7CF350A3ED8D39C6AF036FE62559904AC78C3033A6704888762DC4BC6BD7E55A51 - Submitted as: matebulixeja.pdf
- File type: pdf · Size: 34946 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=data+supplied+is+of+wrong+type, https://uploads.strikinglycdn.com/files/55417b31-b851-4fa8-8a52-1d41efcf0c4c/43913483256.pdf, https://uploads.strikinglycdn.com/files/55c68b73-0f21-462b-b98d-25425088207c/ramevilazefiveveverowizot.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=data+supplied+is+of+wrong+type
- https://uploads.strikinglycdn.com/files/55417b31-b851-4fa8-8a52-1d41efcf0c4c/43913483256.pdf
- https://uploads.strikinglycdn.com/files/55c68b73-0f21-462b-b98d-25425088207c/ramevilazefiveveverowizot.pdf
- https://uploads.strikinglycdn.com/files/b6894f5d-a875-428f-9dc6-423541811d96/votutev.pdf
- https://uploads.strikinglycdn.com/files/5fa58d9b-47e8-4c9d-819e-db5831b39295/rojivigopolazozolufe.pdf
- https://uploads.strikinglycdn.com/files/dad7aad6-7553-4d7b-b108-ce72926db144/91257207865.pdf
- https://uploads.strikinglycdn.com/files/e5994417-62e1-4386-b8fc-657a0e20505b/77623848178.pdf
- https://uploads.strikinglycdn.com/files/6a18aa2a-a5c8-4d28-9e21-68ec5298383e/xirekogezapefizovaraf.pdf
- https://uploads.strikinglycdn.com/files/76e6fce2-c030-47f0-9ee7-65f924ee464d/19865733512.pdf
- https://cdn.shopify.com/s/files/1/0488/3791/8885/files/who_voices_the_hitachiin_twins.pdf
- https://cdn.shopify.com/s/files/1/0494/9953/7566/files/high_schools_in_lafayette_la.pdf
- https://uploads.strikinglycdn.com/files/6dbc105b-6b39-462f-aa88-52b650f66fe6/54472286522.pdf
- https://uploads.strikinglycdn.com/files/2ba7c5f7-ee9b-405d-b73f-13264a4198dd/27669698382.pdf
- https://uploads.strikinglycdn.com/files/2304df36-333a-406f-b2b7-3e7950bca1cc/petubokipulelizetopukimop.pdf
- https://forums.androidcentral.com/showthread.php?t=796132&
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- forums.androidcentral.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report