SUSPICIOUS — sebolix.pdf
SUSPICIOUS — sebolix.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9ca557b363cea38d01f4a8ab9bfb4690335c8209075387f0dea5d76ee4a228b7 - SHA-1:
23f45ea626f2ff46fdfd32a23e99208e07bed12a - MD5:
28b81c2ad44339221ace79e9975cacff - ssdeep:
384:7MsFlS3K6XgKV7cAgdOpW+0EvK9YSEo02Ca2GuG7rWHsLMKAF/GFdCUSFsFC0HGF:AgGzpD1CGp2YG7rW2MKAF/4tJZBJah - TLSH:
T1DD2E7CF351A7ED8C7A8FAB039DE71049610AC38D603AD6B0458C7B3DC4786BD6E50A61 - Submitted as: sebolix.pdf
- File type: pdf · Size: 32432 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=mcdonnell+miller+67+manual, https://site-1038455.mozfiles.com/files/1038455/befowaxex.pdf, https://site-1038794.mozfiles.com/files/1038794/kavubutitiwugiserig.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=mcdonnell+miller+67+manual
- https://site-1038455.mozfiles.com/files/1038455/befowaxex.pdf
- https://site-1038794.mozfiles.com/files/1038794/kavubutitiwugiserig.pdf
- https://site-1041486.mozfiles.com/files/1041486/dawavabidenijutixonofan.pdf
- https://site-1042729.mozfiles.com/files/1042729/4061087515.pdf
- https://uploads.strikinglycdn.com/files/fa9d428a-07ed-434e-929a-77ab53a073a0/sukejer.pdf
- https://uploads.strikinglycdn.com/files/e1640893-ef8d-4b47-9d2e-957e3a4544ab/ronopazitevufutixosir.pdf
- https://uploads.strikinglycdn.com/files/763609ea-87cd-403b-809d-547321527db2/5408074833.pdf
- https://uploads.strikinglycdn.com/files/81ef5944-c4bb-425a-862f-b5a73085ebd4/56484117524.pdf
- https://uploads.strikinglycdn.com/files/f32ba7f1-f115-4832-ad83-9f39a2e3c4de/65851931061.pdf
- https://uploads.strikinglycdn.com/files/1decebe1-286b-4b7a-ac5d-de6db707048f/pepamimirebavupasuseg.pdf
- https://uploads.strikinglycdn.com/files/14e6fc0b-283e-41ff-b348-212655309963/56139619206.pdf
- https://uploads.strikinglycdn.com/files/c8cbb525-5570-4714-8f3f-6935d3a487ca/zibakorivupivutuxawem.pdf
- https://site-1038531.mozfiles.com/files/1038531/46194027005.pdf
- https://site-1036832.mozfiles.com/files/1036832/borejejozowezadibure.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1038455.mozfiles.com
- site-1038794.mozfiles.com
- site-1041486.mozfiles.com
- site-1042729.mozfiles.com
- uploads.strikinglycdn.com
- site-1038531.mozfiles.com
- site-1036832.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report