SUSPICIOUS — xikarow.pdf
SUSPICIOUS — xikarow.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d3d328355f8707bba7083c7eab7a86e42f78f31065c97a9c613828fc8f215763 - SHA-1:
76a7a15042a28ce03ad15c44bdeffaa5edc915a4 - MD5:
41d89cc9da50d67c184a430f00491d7b - ssdeep:
768:mgGzpD3e8El4MjdcWfelRnXPiQFtr+66AnRwZrywL/8xohLB8:zGFDe8lB9aQG66TZrys0xqLB8 - TLSH:
T153327EF750ABDD8C7B879B13B9AB2459718AD7483132DBA00588776C88FC6BDBE00550 - Submitted as: xikarow.pdf
- File type: pdf · Size: 46009 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=volume%20and%20surface%20area%20worksheet%20geometry, https://uploads.strikinglycdn.com/files/1f4c9ee4-0985-4f88-859d-f8f0019c29cd/95474113831.pdf, https://uploads.strikinglycdn.com/files/01660bc4-a09e-476c-a477-96edd27e96a7/jekinubupe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=volume%20and%20surface%20area%20worksheet%20geometry
- https://uploads.strikinglycdn.com/files/1f4c9ee4-0985-4f88-859d-f8f0019c29cd/95474113831.pdf
- https://uploads.strikinglycdn.com/files/01660bc4-a09e-476c-a477-96edd27e96a7/jekinubupe.pdf
- https://uploads.strikinglycdn.com/files/b8cbb14a-55fc-49ae-8e13-1216589437c6/pippin_full_score.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/65d5b005b7c2ba6.pdf
- https://korodaziso.weebly.com/uploads/1/3/0/7/130740443/kaxidirevenuk.pdf
- https://vewusijonaw.weebly.com/uploads/1/3/4/4/134489037/watodikodutex.pdf
- https://lopinelu.weebly.com/uploads/1/3/4/3/134369173/zadolidawitoke_tador_kuwusalenogelix_gonemezeko.pdf
- https://cdn-cms.f-static.net/uploads/4368989/normal_5f91614ed4ded.pdf
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f8e782b1bc14.pdf
- https://cdn-cms.f-static.net/uploads/4391335/normal_5f98a08e6ea02.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f873d97d2c08.pdf
- https://cdn-cms.f-static.net/uploads/4407983/normal_5f953d4f2fd14.pdf
- https://cdn-cms.f-static.net/uploads/4385230/normal_5f8d696e5740f.pdf
- https://cdn-cms.f-static.net/uploads/4366354/normal_5f8826fdc1a3e.pdf
- https://cdn-cms.f-static.net/uploads/4370530/normal_5f8f6534f2cdc.pdf
- https://uploads.strikinglycdn.com/files/47c5c2cd-41bf-4b2e-91a9-bfc837d5b413/27387672705.pdf
- https://uploads.strikinglycdn.com/files/8e4dfe4d-6996-4709-be32-b4a4aad007cf/wetepediramozadud.pdf
- https://uploads.strikinglycdn.com/files/9eb33e00-86b9-4810-85b0-2136951c4d06/jomatula.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- tavumake.weebly.com
- korodaziso.weebly.com
- vewusijonaw.weebly.com
- lopinelu.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report