SUSPICIOUS — gebaxa.pdf
SUSPICIOUS — gebaxa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
783a669c9d15f8d824a6bd4aafcf93ab11c6806fbdcccd19d8e47057e01a1aa8 - SHA-1:
e2c55970259306609cd587b3ab52bfebaf74c0d4 - MD5:
d412383f7fa62b57f588c408978327dd - ssdeep:
768:xgGzpD1kbq8z8sR617fGTi5Fdop+S2NdgnfdsvPe0xey:CGFRk8sR8fB5F6f2Ndgn1svPe0xey - TLSH:
T15D30AFF31187DD8C7A8AAB036EFA2099614DC78D7133A7A449D8776DC0BC5BD6E00821 - Submitted as: gebaxa.pdf
- File type: pdf · Size: 37839 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=how%20to%20find%20brachial%20pulse%20fast, https://uploads.strikinglycdn.com/files/73d653ad-0872-4f3c-b6c4-bb212206d35e/financial_statement_template_excel_philippines.pdf, https://jilibawijoza.weebly.com/uploads/1/3/4/3/134363321/zitiligivavobepexa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=how%20to%20find%20brachial%20pulse%20fast
- https://uploads.strikinglycdn.com/files/73d653ad-0872-4f3c-b6c4-bb212206d35e/financial_statement_template_excel_philippines.pdf
- https://jilibawijoza.weebly.com/uploads/1/3/4/3/134363321/zitiligivavobepexa.pdf
- https://cdn-cms.f-static.net/uploads/4368468/normal_5f8b37ea4d082.pdf
- https://s3.amazonaws.com/metubevozisul/2018_telugu_calendar_download.pdf
- https://uploads.strikinglycdn.com/files/be06d75e-742a-4f3e-83cb-26186e22c288/58293944495.pdf
- https://uploads.strikinglycdn.com/files/07692499-1730-4ff7-b20d-b82ed82328e1/blackberry_bold_9900_review.pdf
- https://uploads.strikinglycdn.com/files/883fc8b8-68ad-45f5-b1e6-155e327f9fd7/54522106495.pdf
- https://s3.amazonaws.com/dugibabafod/asme_valve_standards.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/6dec1b6ff30ff0.pdf
- https://uploads.strikinglycdn.com/files/5180ca62-a789-4c0b-8dad-b43c20f73a1d/6172286788.pdf
- https://cdn-cms.f-static.net/uploads/4376125/normal_5fa15ada2e7a2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- jilibawijoza.weebly.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- dejolezeg.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report