SUSPICIOUS — xunug-tizozakusul.pdf
SUSPICIOUS — xunug-tizozakusul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f3c7894544409c00f8f97f319c6f9a55bcc448af50658327b63ec2cf3ac77028 - SHA-1:
cec84976ba278fefa48baa60c8f758ffb9f104a6 - MD5:
6ed7e380920590523ea9c3911bdc8137 - ssdeep:
768:DgGzpDopfcSpeDdJiW6GmUgJJyFZXSi3+MF/UQ8ldXKUOybY6HhiO/Z6YqjA:8GF8pEJXiirRUBldXKUO16EO/Z6YqjA - TLSH:
T1A5328DF310A7ED4C3E8B9B83ADAB05A86089C74972369350548C776CD4BC5BEAF00970 - Submitted as: xunug-tizozakusul.pdf
- File type: pdf · Size: 44088 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ampli%20de%20puissance%20pdf, https://uploads.strikinglycdn.com/files/67e1aa02-5d8c-4337-898a-6ca267907596/80899400853.pdf, https://uploads.strikinglycdn.com/files/1ca539a0-8078-4163-bcd6-cd9c4df179f0/jarasaludedaso.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ampli%20de%20puissance%20pdf
- https://uploads.strikinglycdn.com/files/67e1aa02-5d8c-4337-898a-6ca267907596/80899400853.pdf
- https://uploads.strikinglycdn.com/files/1ca539a0-8078-4163-bcd6-cd9c4df179f0/jarasaludedaso.pdf
- https://uploads.strikinglycdn.com/files/8ac701da-87c0-438c-9558-f17b8ea7f771/45950245660.pdf
- https://uploads.strikinglycdn.com/files/03104851-a28e-4ad1-98e2-6108a3ca3b8d/52247327762.pdf
- https://uploads.strikinglycdn.com/files/4af0fd09-ee7b-44f6-a841-4e5caa7cb21c/lenguaje_algebraico_ejercicios_resue.pdf
- https://uploads.strikinglycdn.com/files/29ea1170-246b-4f90-8e10-810463f44101/malegalabinusafijavutura.pdf
- https://uploads.strikinglycdn.com/files/f2b2f2e9-f162-4da1-99b3-4bd7754d9a1c/74934866599.pdf
- https://cdn-cms.f-static.net/uploads/4373504/normal_5f8ac13a23d60.pdf
- https://cdn-cms.f-static.net/uploads/4385434/normal_5f922a081f886.pdf
- https://cdn-cms.f-static.net/uploads/4393911/normal_5f90b8e4ecbb0.pdf
- https://cdn-cms.f-static.net/uploads/4369629/normal_5f8b580c614a4.pdf
- https://cdn-cms.f-static.net/uploads/4370265/normal_5f8ec2196391a.pdf
- https://cdn.shopify.com/s/files/1/0430/9411/4455/files/ny_real_property_tax_credit.pdf
- https://cdn.shopify.com/s/files/1/0481/9632/1432/files/56887075701.pdf
- https://cdn.shopify.com/s/files/1/0499/0415/6830/files/inside_out_games_sydney.pdf
- https://cdn.shopify.com/s/files/1/0484/3438/0968/files/13750403825.pdf
- https://cdn.shopify.com/s/files/1/0492/2844/7900/files/lebagugixepuripa.pdf
- https://s3.amazonaws.com/xenavuxa/autoclave_parts.pdf
- https://s3.amazonaws.com/donake/burisasewa.pdf
- https://cdn-cms.f-static.net/uploads/4390056/normal_5f920a6eaf52c.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f8844d1a1f20.pdf
- https://cdn-cms.f-static.net/uploads/4404285/normal_5f91599434f3a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report