SUSPICIOUS — tivesexoroxa.pdf
SUSPICIOUS — tivesexoroxa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4b88593de00031ea6741641d87a99e9c1041714c6ef6bf071b7b62022e1430a9 - SHA-1:
b465c57189a47c3a1668cf5357f62b49351a0527 - MD5:
9d548c3242e566f66cedfcc6b6ad733c - ssdeep:
768:OgGzpDPpG1OHzYDMGGlRWTQU8aRK+UdQXen9nl66kYpPS/5EbyJvRdd83y4U:rGFTpJRiQzaJvXen9l66k5QyndGy4U - TLSH:
T13C31AEF341ABFD8C3AC79B13ADAB21185085C78862369768188D7B6CD4BC7FC6E01561 - Submitted as: tivesexoroxa.pdf
- File type: pdf · Size: 42454 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=sketch%20drawing%20step%20by%20step%20pdf, https://cdn-cms.f-static.net/uploads/4382186/normal_5f8e5f97eb651.pdf, https://cdn-cms.f-static.net/uploads/4408461/normal_5f9756e299450.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=sketch%20drawing%20step%20by%20step%20pdf
- https://cdn-cms.f-static.net/uploads/4382186/normal_5f8e5f97eb651.pdf
- https://cdn-cms.f-static.net/uploads/4408461/normal_5f9756e299450.pdf
- https://cdn-cms.f-static.net/uploads/4384028/normal_5f8d339ab02e3.pdf
- https://uploads.strikinglycdn.com/files/6e7b712c-f5cb-431f-973d-40e65d8cfa15/ffxiv_flower_pot.pdf
- https://uploads.strikinglycdn.com/files/9fde1a2e-5932-46f3-ad0d-28458c8c5d53/76278745457.pdf
- https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/29932f71.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/666c4a.pdf
- https://cdn.shopify.com/s/files/1/0487/7248/1190/files/dowolekipom.pdf
- https://cdn.shopify.com/s/files/1/0428/9580/2527/files/10695655887.pdf
- https://wozuwonasanava.weebly.com/uploads/1/3/1/4/131483955/nimovafoladux.pdf
- https://kesevaze.weebly.com/uploads/1/3/1/3/131383297/2440739.pdf
- https://uploads.strikinglycdn.com/files/9df508cb-51d8-4e6c-b240-c7b667e20081/xonepesawewekonamajiwat.pdf
- https://uploads.strikinglycdn.com/files/9f396722-25a9-48be-b324-d85f71f871cc/death_orb_dead_cells.pdf
- https://uploads.strikinglycdn.com/files/8976013e-c74d-4ece-95d4-49b38b47d2ce/13277446750.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- xuvakaxatal.weebly.com
- jamuseramomuf.weebly.com
- cdn.shopify.com
- wozuwonasanava.weebly.com
- kesevaze.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report