SUSPICIOUS — dabiviko.pdf
SUSPICIOUS — dabiviko.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
ffa14f4afd88e509332521237430c1a531a45a6ef610d3c3a4c22f3cb5496502 - SHA-1:
e8217fb96dee28254570e33783b047b32ecce6d1 - MD5:
485a778d1e7ac0b968cfad254c05cf8f - ssdeep:
1536:BGFwpjsmTmpKnwd3x246JlmI7HHb0+ZlPWE1:kFwpjsmw9x6Jl17HH3nb - TLSH:
T14E35CFF35083DD8C3ACBAB036EAA1049A04AC74C61369B60549D773CD9BC6FCBD419A1 - Submitted as: dabiviko.pdf
- File type: pdf · Size: 60305 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=re2%20super%20tyrant, https://uploads.strikinglycdn.com/files/2fee46ca-aedc-45dc-a4e7-24ebc960b310/72594034197.pdf, https://uploads.strikinglycdn.com/files/42cfe174-586c-463d-ac28-c515ce2b1a44/62897714954.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=re2%20super%20tyrant
- https://uploads.strikinglycdn.com/files/2fee46ca-aedc-45dc-a4e7-24ebc960b310/72594034197.pdf
- https://uploads.strikinglycdn.com/files/42cfe174-586c-463d-ac28-c515ce2b1a44/62897714954.pdf
- https://uploads.strikinglycdn.com/files/102f05e9-e5a1-41cd-9975-607a7c627916/20914547528.pdf
- https://uploads.strikinglycdn.com/files/243c2aa4-4e19-42e4-860a-173885fe5345/64570561510.pdf
- https://uploads.strikinglycdn.com/files/a38c9ccd-8d1e-4d4e-8ac5-8c01e529285b/ejercicios_valores_del_se_2o_bachill.pdf
- https://fanawilixu.weebly.com/uploads/1/3/1/4/131408209/c80b73.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/3afa756b.pdf
- https://cdn.shopify.com/s/files/1/0503/0563/0404/files/zarikatafagelijorefod.pdf
- https://cdn.shopify.com/s/files/1/0495/2018/1414/files/it_works_double_diamond_chart.pdf
- https://cdn.shopify.com/s/files/1/0436/4845/0718/files/45902846774.pdf
- https://cdn.shopify.com/s/files/1/0436/1037/4307/files/38542596031.pdf
- https://cdn.shopify.com/s/files/1/0482/9924/5723/files/zeribomebenavod.pdf
- https://uploads.strikinglycdn.com/files/b5d00573-898c-430f-9e58-ad562f2575f1/17208078809.pdf
- https://uploads.strikinglycdn.com/files/0a25eb63-55cb-4962-9d92-011b013777b2/zovibinogusibowuma.pdf
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/zelap.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/6079293.pdf
- https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/404c04508b6b89.pdf
- https://cdn-cms.f-static.net/uploads/4370307/normal_5f8b5d81ca9da.pdf
- https://cdn-cms.f-static.net/uploads/4373297/normal_5f8898a3863ca.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- fanawilixu.weebly.com
- xazapadikud.weebly.com
- cdn.shopify.com
- xifobosakup.weebly.com
- kabudededawizo.weebly.com
- lowizozexide.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report