SUSPICIOUS — xoxulobej-kikizidusa.pdf
SUSPICIOUS — xoxulobej-kikizidusa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ea577259c3681a59de947ceb85e8d34fe269da7a9eecf267c1a982294ea7f26d - SHA-1:
fe981a799ec7048db704da87c91df07fe3aa31e3 - MD5:
45b2d12450ac4548fca1db75c952d5d2 - ssdeep:
768:/gGzpDspPqdxfNO+2/3jV+D8Upir+Q2JmwXXA3E+SWvTX:IGFYpCC+zJmwXQU+SWvTX - TLSH:
T16F2F5DF79067ED8C7A8B9F035DBA11AD9449C78D512397A054887B2CC4BC6ED7F01620 - Submitted as: xoxulobej-kikizidusa.pdf
- File type: pdf · Size: 34102 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=new%20york%20guide, https://uploads.strikinglycdn.com/files/54aa21f7-590a-4644-8f77-402fc27ccca4/xenebopoz.pdf, https://uploads.strikinglycdn.com/files/bf755c85-e2f5-4af5-8e83-edc105dd2709/sanam_re_sanam_re_mp3_free_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=new%20york%20guide
- https://uploads.strikinglycdn.com/files/54aa21f7-590a-4644-8f77-402fc27ccca4/xenebopoz.pdf
- https://uploads.strikinglycdn.com/files/bf755c85-e2f5-4af5-8e83-edc105dd2709/sanam_re_sanam_re_mp3_free_download.pdf
- https://uploads.strikinglycdn.com/files/0615ec19-3d49-4d8f-af6f-b3bc2b018c35/buwipopodifozikopemovadig.pdf
- https://cdn.shopify.com/s/files/1/0498/1702/6715/files/download_nova_launcher_prime_apkmirror.pdf
- https://cdn.shopify.com/s/files/1/0501/0613/8787/files/dupray_steam_cleaner_instructions.pdf
- https://cdn-cms.f-static.net/uploads/4375087/normal_5f8b7e35d6877.pdf
- https://cdn-cms.f-static.net/uploads/4367313/normal_5f8955dfad75b.pdf
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f8b568cbde04.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f874e04222a6.pdf
- https://cdn-cms.f-static.net/uploads/4369487/normal_5f8978d10a1b3.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f86ffde8176c.pdf
- https://cdn-cms.f-static.net/uploads/4370777/normal_5f88c319d512d.pdf
- https://cdn-cms.f-static.net/uploads/4369499/normal_5f883eed83454.pdf
- https://cdn-cms.f-static.net/uploads/4367305/normal_5f87380edb0f3.pdf
- https://cdn-cms.f-static.net/uploads/4368227/normal_5f8ba3b26d864.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f86fea03154f.pdf
- https://cdn-cms.f-static.net/uploads/4368223/normal_5f892bcb79138.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report