SUSPICIOUS — fubaxin.pdf
SUSPICIOUS — fubaxin.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b5535c5d4f2076001b8f10dc725271695a4815032dff30e9fd04344c5b88533f - SHA-1:
112f46d41c0430e7c29f64a9f5e120d847e141c7 - MD5:
6b3482bf175762866b318ead514548dc - ssdeep:
768:HgGzpDfe1078ygwhO/5afYlXVhRegIi8oc2InLL6L5ht+xuU3iuv7Dee:AGFDe1Lv8oTILL6LftyuU3iujDee - TLSH:
T168329EF310A7DD8C7BCA9B039DEB005A5185D7886232E6644498BB6CD47C3FD7E10A21 - Submitted as: fubaxin.pdf
- File type: pdf · Size: 45308 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=textbook%20of%20veterinary%20anatomy%20pdf, https://cdn.shopify.com/s/files/1/0497/4231/5669/files/i_gotta_feeling_lyrics_youtube.pdf, https://cdn.shopify.com/s/files/1/0433/7260/9686/files/body_in_white_tesla.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=textbook%20of%20veterinary%20anatomy%20pdf
- https://cdn.shopify.com/s/files/1/0497/4231/5669/files/i_gotta_feeling_lyrics_youtube.pdf
- https://cdn.shopify.com/s/files/1/0433/7260/9686/files/body_in_white_tesla.pdf
- https://cdn.shopify.com/s/files/1/0499/8620/7894/files/4931429703.pdf
- https://cdn.shopify.com/s/files/1/0433/3348/4702/files/sokalomofulefobozul.pdf
- https://cdn.shopify.com/s/files/1/0430/9699/8048/files/edmonds_ferry_terminal_status.pdf
- https://cdn.shopify.com/s/files/1/0433/9544/8988/files/50387684334.pdf
- https://cdn.shopify.com/s/files/1/0434/7733/6224/files/xitikugizorepexosexoj.pdf
- https://cdn.shopify.com/s/files/1/0438/3437/6352/files/rakolixuxizuduvipale.pdf
- https://cdn.shopify.com/s/files/1/0429/7090/6780/files/sd_maid_pro_unlocker_apk_4.4.0.pdf
- https://cdn.shopify.com/s/files/1/0485/2364/0987/files/eaton_9170_ups_manual.pdf
- https://site-1039621.mozfiles.com/files/1039621/toxodidipifibibipakutim.pdf
- https://site-1039438.mozfiles.com/files/1039438/92125881249.pdf
- https://cdn.shopify.com/s/files/1/0435/4975/3493/files/table_saw_push_block_plans.pdf
- https://cdn.shopify.com/s/files/1/0492/3949/0726/files/wicked_eyes_and_wicked_hearts_complete_guide.pdf
- https://uploads.strikinglycdn.com/files/8b6a8f00-da9d-42d2-9bc5-d1bfac613b90/16568660190.pdf
- https://uploads.strikinglycdn.com/files/af0545dd-4fb2-4a85-9d29-dd8e9de11010/lokig.pdf
- https://uploads.strikinglycdn.com/files/6ad5b7a5-9c72-41c8-9dd7-3466998f9dc3/88772965583.pdf
- https://cdn.shopify.com/s/files/1/0485/7964/1504/files/52610078384.pdf
- https://cdn.shopify.com/s/files/1/0498/7309/2766/files/realidades_4_workbook_answer_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1039621.mozfiles.com
- site-1039438.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report