SUSPICIOUS — xenote.pdf
SUSPICIOUS — xenote.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
78232f469610b8b336a1f6fe11977881afc180e3ff78c8e870bf7fb2367690a9 - SHA-1:
c40b6ffd876648362b9d8c0ab1645d5916be61c6 - MD5:
a01b3c9da4b79f905e067860ddba9fbd - ssdeep:
768:5gGzpDEedkhUbswZc1A6+hgwZw5If1nVbiVZi03OG5y8fV1:6GFQedki6UgwO50VbiVd3OGffV1 - TLSH:
T18D327EF350D7ED8C7A8BEF47AEB71198608ED74D213297A054C87A2DD07C6AE6E00950 - Submitted as: xenote.pdf
- File type: pdf · Size: 43265 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=toddler%20glove%20pattern%20sewing, https://cdn-cms.f-static.net/uploads/4366003/normal_5f8706da29e4e.pdf, https://cdn-cms.f-static.net/uploads/4368228/normal_5f87620b944b8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=toddler%20glove%20pattern%20sewing
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f8706da29e4e.pdf
- https://cdn-cms.f-static.net/uploads/4368228/normal_5f87620b944b8.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f87258e260b0.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f871a6ea252b.pdf
- https://cdn-cms.f-static.net/uploads/4368736/normal_5f8893044d620.pdf
- https://uploads.strikinglycdn.com/files/857df056-4639-4eff-a443-77b267b616be/33278298178.pdf
- https://uploads.strikinglycdn.com/files/cc2bc735-2d21-434a-83ca-1e8efcdf90d9/dikalaxasokodujavokow.pdf
- https://uploads.strikinglycdn.com/files/2dcd55d4-afad-4862-a748-2863c3e7c926/bitijageb.pdf
- https://uploads.strikinglycdn.com/files/d3a0aeaa-405b-45a7-a3df-7f39e8cc99fe/kizunorudatewulabimeki.pdf
- https://uploads.strikinglycdn.com/files/f84a66e7-8985-42fd-941a-6f415ff20a89/kipewamonimejago.pdf
- https://uploads.strikinglycdn.com/files/3f6cb5d3-0bb1-4717-a2e4-5d74515df1e0/dasugodovevawujapalugeke.pdf
- https://site-1043967.mozfiles.com/files/1043967/95371066981.pdf
- https://site-1043576.mozfiles.com/files/1043576/96470582869.pdf
- https://site-1039804.mozfiles.com/files/1039804/lebovimedado.pdf
- https://site-1036719.mozfiles.com/files/1036719/vebutojofulipes.pdf
- https://site-1044026.mozfiles.com/files/1044026/puwusujeniwijalovagunewi.pdf
- https://site-1042360.mozfiles.com/files/1042360/99042446257.pdf
- https://uploads.strikinglycdn.com/files/489b6e14-3ac5-416b-a4cb-bca5a79d57eb/45140647766.pdf
- https://uploads.strikinglycdn.com/files/2c4b9ca0-f264-41ef-bf52-8096c875c268/bebotagozazuvojegizesu.pdf
- https://uploads.strikinglycdn.com/files/66e8426f-20bd-4337-b826-6b6899b76b0a/77009843903.pdf
- https://uploads.strikinglycdn.com/files/c999c1e1-0e48-4f69-a4b8-e8e64a78329e/22382816952.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1043967.mozfiles.com
- site-1043576.mozfiles.com
- site-1039804.mozfiles.com
- site-1036719.mozfiles.com
- site-1044026.mozfiles.com
- site-1042360.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report