SUSPICIOUS — kipaxe.pdf
SUSPICIOUS — kipaxe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
507d641f60d3e14dab5401c526bad9b98fd9b730b7f71ceade3f3c81378552da - SHA-1:
024a8bc8e9fc1056cbe26680ab77872cf2b45dfe - MD5:
3e68214814e63b8afcaf344865f10127 - ssdeep:
3072:8FipQ0fU7PYF4J/gpxq7Rc+OZyKir4LKJX19MMiHfcZaWRo4M:0cQGUjYF4VuL+OZCsOJX1SMuf2a - TLSH:
T1BE3D02F760B3EE092A97975399E214D810C4D34A21617EF049D5BBACC87C6BE3E40A61 - Submitted as: kipaxe.pdf
- File type: pdf · Size: 133522 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=les+fleurs+du+mal+th%25C3%25A8mes, https://site-1044440.mozfiles.com/files/1044440/12184883561.pdf, https://site-1037103.mozfiles.com/files/1037103/72668704894.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=les+fleurs+du+mal+th%25C3%25A8mes
- https://site-1044440.mozfiles.com/files/1044440/12184883561.pdf
- https://site-1037103.mozfiles.com/files/1037103/72668704894.pdf
- https://site-1040179.mozfiles.com/files/1040179/25019128282.pdf
- https://site-1036969.mozfiles.com/files/1036969/9748516774.pdf
- https://site-1039492.mozfiles.com/files/1039492/bokelavuwulediw.pdf
- https://site-1037235.mozfiles.com/files/1037235/30302155558.pdf
- https://site-1043791.mozfiles.com/files/1043791/12498254326.pdf
- https://site-1041846.mozfiles.com/files/1041846/40778774474.pdf
- https://site-1037221.mozfiles.com/files/1037221/4387156651.pdf
- https://site-1037096.mozfiles.com/files/1037096/84210433266.pdf
- https://site-1037142.mozfiles.com/files/1037142/49073815560.pdf
- https://site-1041690.mozfiles.com/files/1041690/latipotidalatim.pdf
- https://site-1037885.mozfiles.com/files/1037885/92971496191.pdf
- https://cdn.shopify.com/s/files/1/0432/5346/5243/files/felig.pdf
- https://cdn.shopify.com/s/files/1/0436/9825/8073/files/35253544285.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1044440.mozfiles.com
- site-1037103.mozfiles.com
- site-1040179.mozfiles.com
- site-1036969.mozfiles.com
- site-1039492.mozfiles.com
- site-1037235.mozfiles.com
- site-1043791.mozfiles.com
- site-1041846.mozfiles.com
- site-1037221.mozfiles.com
- site-1037096.mozfiles.com
- site-1037142.mozfiles.com
- site-1041690.mozfiles.com
- site-1037885.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report