SUSPICIOUS — xekix_gipuzu.pdf
SUSPICIOUS — xekix_gipuzu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a35b956b07de212eb7d6caa1ecc6b2b584d26007660c4c369427272ef57f4cec - SHA-1:
c913cc104d01198049e94c1a10ad0eed0242805c - MD5:
9e4e2a5806b08fef4a2b3837c6c57eb2 - ssdeep:
768:KgGzpDDp5xnakN9Jlm3JOeCcZFszpsyPFDGK2lINMEqLgk8T9C53v/8q6r9Hr:XGF/pjakhluJ6qMQK2m+EiNB53vX4r - TLSH:
T186318EF351A3DD8D7686EF076AAE281D6149E7889132577485C87B2CC4BC3BE2F10960 - Submitted as: xekix_gipuzu.pdf
- File type: pdf · Size: 41614 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=desperte%20gigante%20interior%20pdf, https://uploads.strikinglycdn.com/files/037e277e-9cc9-4929-83cd-92ea5f702dd0/lovestruck_the_musical_songs_download.pdf, https://uploads.strikinglycdn.com/files/e7757032-c3e1-4749-a432-08ad19ca8272/10_steps_to_learn_anything_quickly.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=desperte%20gigante%20interior%20pdf
- https://uploads.strikinglycdn.com/files/037e277e-9cc9-4929-83cd-92ea5f702dd0/lovestruck_the_musical_songs_download.pdf
- https://uploads.strikinglycdn.com/files/e7757032-c3e1-4749-a432-08ad19ca8272/10_steps_to_learn_anything_quickly.pdf
- https://uploads.strikinglycdn.com/files/917765cc-10d5-4ef0-b097-f01e43bd9eb2/pobipagitilidemiwu.pdf
- https://uploads.strikinglycdn.com/files/04c6a5b2-1975-47b7-a842-00e0124a2118/82796049356.pdf
- https://cdn.shopify.com/s/files/1/0493/2186/9471/files/57970128496.pdf
- https://cdn.shopify.com/s/files/1/0431/8140/8416/files/mexican_hat_dance_song_guitar_tabs.pdf
- https://s3.amazonaws.com/fasanag/pandoc_markdown_to_command.pdf
- https://s3.amazonaws.com/jadere/spring_boot_annotations_list_with_explanation.pdf
- https://s3.amazonaws.com/sezebepit/tendinitis_aquiliana_tratamiento.pdf
- https://cdn.shopify.com/s/files/1/0502/3937/3501/files/nukugemax.pdf
- https://cdn.shopify.com/s/files/1/0496/1180/0729/files/e_flat_major_chord_guitar.pdf
- https://cdn.shopify.com/s/files/1/0476/5502/6854/files/tewifesudumukore.pdf
- https://mupawume.weebly.com/uploads/1/3/4/3/134365579/662726.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zuvefusu_tewojawowebav.pdf
- https://s3.amazonaws.com/fejenijovekozu/ridikexaduzeponud.pdf
- https://s3.amazonaws.com/lunojol/82833699274.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- 5d.ca
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- mupawume.weebly.com
- jawasolasazilem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report