SUSPICIOUS — xipesexubata.pdf
SUSPICIOUS — xipesexubata.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
caea02f3fed9e8ee63663c9efc4a2db4a72178abd63b51467eba15bbcfe8ebb9 - SHA-1:
9cbff127b0b1d4a40041c2e120c4312f790838cb - MD5:
fc8b0b608fe9e81834fa78e72aa9cb8a - ssdeep:
768:+gGzpDZy4tImw6/hUS9UbfLtgFiX1HhSw8+1mKQx5A1LUB9awSU1H6w:7GFpC0U+gCFilHIw8Dx5A1I+wh1H6w - TLSH:
T1E835C0F3109BDD8579A66F03A6F7145C754BD68C7032CA946AC877AC88BC5BC6E10CA0 - Submitted as: xipesexubata.pdf
- File type: pdf · Size: 60803 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=maiya%20yashoda%20mp3%20song%20download, https://uploads.strikinglycdn.com/files/f389f6eb-a550-424c-a9c1-d0535b2f846e/bozozedejudi.pdf, https://uploads.strikinglycdn.com/files/6072030c-8886-4bea-8806-275c94b5616a/wafegudakuniseli.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=maiya%20yashoda%20mp3%20song%20download
- https://uploads.strikinglycdn.com/files/f389f6eb-a550-424c-a9c1-d0535b2f846e/bozozedejudi.pdf
- https://s3.amazonaws.com/vavebufevodutob/celestion_g12t-75_made_in_england.pdf
- https://uploads.strikinglycdn.com/files/6072030c-8886-4bea-8806-275c94b5616a/wafegudakuniseli.pdf
- https://uploads.strikinglycdn.com/files/3f132b25-c3dc-4c1c-9412-c1f9c2f7a5cc/wulujezewotomoseti.pdf
- https://uploads.strikinglycdn.com/files/32e744e1-a2ed-48f2-a0aa-a54d6fd065bd/sugewetoru.pdf
- https://uploads.strikinglycdn.com/files/ef25c903-d0f3-4e4f-b349-7920ba8a565e/pathfinder_strategy_guide.pdf
- https://uploads.strikinglycdn.com/files/05654d3e-a768-42c7-8640-4f650bac0256/birches_poem_line_by_line_explanation.pdf
- https://uploads.strikinglycdn.com/files/f614dae8-0a08-47e7-9596-b0f8efaf4f5a/66647587361.pdf
- https://s3.amazonaws.com/fovezewi/systematic_review_handbook.pdf
- https://uploads.strikinglycdn.com/files/889c2e95-5195-46e2-8338-a0b4ef9f49ec/6284793358.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report