SUSPICIOUS — bixebol.pdf
SUSPICIOUS — bixebol.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9da4efafcc67c0bdc41db63f061ef631b0ff9a2278ab2684ddb68f721a31b6ad - SHA-1:
2b824993b189bf9436e03f86b2276e4e8f07fb3d - MD5:
f6e446743db381307887818b181cbb76 - ssdeep:
768:xgGzpDxu89hekGD/RQpn81maDD8Uf+RkEk+L/wJiyJ/nPE6DtvCsqHCN0fRB8:CGFVw08lFokGu9E6D0sqHCN0fR+ - TLSH:
T16E31BEF3909BFDCD7A82AB136E7605596588D38CB132AA6059CC776CC47C1BE6E00830 - Submitted as: bixebol.pdf
- File type: pdf · Size: 43156 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://nipaxibovaj.weebly.com/uploads/1/3/1/3/131379211/25c04ef.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=digital%20signature%20form%20sify%20pdf, https://cdn-cms.f-static.net/uploads/4367921/normal_5f970ab6b2965.pdf, https://cdn.shopify.com/s/files/1/0439/2130/9851/files/57592287328.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=digital%20signature%20form%20sify%20pdf
- https://cdn-cms.f-static.net/uploads/4367921/normal_5f970ab6b2965.pdf
- https://s3.amazonaws.com/panalipolifod/que_es_un_metro_lineal.pdf
- https://cdn.shopify.com/s/files/1/0439/2130/9851/files/57592287328.pdf
- https://cdn.shopify.com/s/files/1/0503/6448/1693/files/falcon_pi_player_docker.pdf
- https://cdn-cms.f-static.net/uploads/4378628/normal_5f8bfcc94e97e.pdf
- https://s3.amazonaws.com/gajabedafot/ruvisapolaruronolijogo.pdf
- https://nipaxibovaj.weebly.com/uploads/1/3/1/3/131379211/25c04ef.pdf
- https://cdn.shopify.com/s/files/1/0433/5304/7195/files/epic_seven_specialty_change_guide.pdf
- https://vebifejelib.weebly.com/uploads/1/3/0/7/130775119/1c51848932.pdf
- https://sizukejagu.weebly.com/uploads/1/3/2/6/132681884/7d7d687212.pdf
- https://cdn-cms.f-static.net/uploads/4380867/normal_5f95452066c32.pdf
- https://cdn.shopify.com/s/files/1/0433/8548/7516/files/15957566182.pdf
- https://vivazezege.weebly.com/uploads/1/3/4/0/134041722/c3a9860aff06.pdf
- https://cdn-cms.f-static.net/uploads/4414360/normal_5f9b189591fd4.pdf
- https://s3.amazonaws.com/nawuvud/naubuc_elementary_school.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- cdn.shopify.com
- nipaxibovaj.weebly.com
- vebifejelib.weebly.com
- sizukejagu.weebly.com
- vivazezege.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report