SUSPICIOUS — riroxogozipup.pdf
SUSPICIOUS — riroxogozipup.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
5ed60653682097769367a33139ad0548e6f0016820fc7b8e505c9c202ce09f43 - SHA-1:
2c9bb9280de3af3d53eec8944435a67bbe47e29d - MD5:
ced5c0700484c58da5810fd5832184fd - ssdeep:
768:nogGzpD9pU+t/3nsk+fHp3jV0pXsjOwnXvFm0a3sKw1kTiRi9rvWkTrCiLJWwg4:lGFZpGOgtq5wkiRi9rvWkXLEwg4 - TLSH:
T13E328DF390A7DD9C3A8BAB57AEE71158204AD78971339BA044CC3B2CC47C6ED6E10950 - Submitted as: riroxogozipup.pdf
- File type: pdf · Size: 46330 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=rahman%20ya%20rahman%20lyrics%20in%20english, https://uploads.strikinglycdn.com/files/b8b8ad03-a6bc-45b1-ae24-0168f7cdec64/26947736570.pdf, https://uploads.strikinglycdn.com/files/41c7761f-46dc-4912-b5c1-436f306856af/xagenapawudapegukefonixa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=rahman%20ya%20rahman%20lyrics%20in%20english
- https://uploads.strikinglycdn.com/files/b8b8ad03-a6bc-45b1-ae24-0168f7cdec64/26947736570.pdf
- https://uploads.strikinglycdn.com/files/41c7761f-46dc-4912-b5c1-436f306856af/xagenapawudapegukefonixa.pdf
- https://uploads.strikinglycdn.com/files/63ff6aea-04f5-4384-be48-c82758228bad/64596318325.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f887d2b49b37.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f8704b77f581.pdf
- https://cdn-cms.f-static.net/uploads/4367017/normal_5f874c78b1928.pdf
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f87c46e97d51.pdf
- https://cdn-cms.f-static.net/uploads/4370076/normal_5f88acb288178.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f871daaeb7ce.pdf
- https://cdn-cms.f-static.net/uploads/4369901/normal_5f87f330df51f.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f8726511f2a3.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f87bb1470e6c.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f8783b549ce8.pdf
- https://site-1038520.mozfiles.com/files/1038520/tuvapanolanobifexa.pdf
- https://site-1042922.mozfiles.com/files/1042922/1826205458.pdf
- https://cdn.shopify.com/s/files/1/0432/3927/6699/files/vimodujapo.pdf
- https://cdn.shopify.com/s/files/1/0500/1845/1609/files/36718663665.pdf
- https://cdn.shopify.com/s/files/1/0499/1805/0472/files/lesomijej.pdf
- https://cdn.shopify.com/s/files/1/0432/2823/3883/files/tolokamotekup.pdf
- https://cdn.shopify.com/s/files/1/0501/6407/2613/files/36863066349.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1038520.mozfiles.com
- site-1042922.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report