SUSPICIOUS — sikej.pdf
SUSPICIOUS — sikej.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
904ba253eb2e248912b859047eb741e8ccc8dac506d4eb88798bb5d173fc380c - SHA-1:
3d418055ac72df5d812dc05d83a5eca8de782a59 - MD5:
4ea9a62dada8972260639ecabfb3c692 - ssdeep:
1536:lGFHVmIbDMaIuyBtBd2PRS/aQNMyWUTF6Mjoxoz:4FHVDMaI3tOEaMMy/F6Mkxc - TLSH:
T11836C0F341ABDD487B8A9B03ACF53968614AC7586033DB6055C97BACC8BC2BD6E50C50 - Submitted as: sikej.pdf
- File type: pdf · Size: 64810 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffnew.ru/wb?keyword=oc%20swimming%20pool, https://vodiwisilob.weebly.com/uploads/1/3/2/6/132681054/kilosozajoxipofuwu.pdf, https://cdn-cms.f-static.net/uploads/4380692/normal_5f8d8784eb1d8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffnew.ru/wb?keyword=oc%20swimming%20pool
- https://vodiwisilob.weebly.com/uploads/1/3/2/6/132681054/kilosozajoxipofuwu.pdf
- https://cdn-cms.f-static.net/uploads/4380692/normal_5f8d8784eb1d8.pdf
- https://cdn-cms.f-static.net/uploads/4368478/normal_5f881fbfd8966.pdf
- https://cdn-cms.f-static.net/uploads/4413713/normal_5fa1a4532b9c9.pdf
- https://uploads.strikinglycdn.com/files/93ee5391-2e20-420e-88eb-4f2966781ae2/gokuridi.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/71ab96.pdf
- https://uploads.strikinglycdn.com/files/be6fb619-3512-423f-be55-1d378e303d4f/64541755761.pdf
- https://cdn-cms.f-static.net/uploads/4463792/normal_5fa4f415a2465.pdf
- https://ruwalabipuges.weebly.com/uploads/1/3/4/4/134465281/9106106.pdf
- https://cdn-cms.f-static.net/uploads/4387040/normal_5f926774240ea.pdf
- https://s3.amazonaws.com/felasorarabipis/dart_tutorial_for_flutter.pdf
- https://gewosawoma.weebly.com/uploads/1/3/0/7/130739201/ripakopapifeven-putagineninufe-duveworos-kudaso.pdf
- https://xilorufanil.weebly.com/uploads/1/3/0/7/130739938/4b34ede87a7c2e5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffnew.ru
- vodiwisilob.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- pavowojavujide.weebly.com
- ruwalabipuges.weebly.com
- s3.amazonaws.com
- gewosawoma.weebly.com
- xilorufanil.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report