SUSPICIOUS — menojeluv_fitejezifug.pdf
SUSPICIOUS — menojeluv_fitejezifug.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
18bb699ffcf38fcfd8dcd97f7316397b576e010d0acd9557b83bfbdf325cfcb1 - SHA-1:
d01e1a295a28cacb43271d91db73980222ecd175 - MD5:
0be8dca93fab8f77aed94c084640bb01 - ssdeep:
768:8gGzpDBp2v1i8zSGBA4DheJONH+gCVhoXY/5OTZqOf43FA7LOn1YbcPuKUXsLT1p:ZGF9p6eZaXUOTd6AGn1YbvKU8LT1veE - TLSH:
T1AA34AEF3419BED4D7986AF03ADEA34199089D74CA23296A054CC7A2DC47C2BD7F50A70 - Submitted as: menojeluv_fitejezifug.pdf
- File type: pdf · Size: 55094 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=free%20patterns%20background, https://cdn.shopify.com/s/files/1/0440/6041/0021/files/king_soopers_castle_rock_bakery.pdf, https://cdn.shopify.com/s/files/1/0498/5428/3931/files/borderlands_2_salvador_build_pistol.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=free%20patterns%20background
- https://cdn.shopify.com/s/files/1/0440/6041/0021/files/king_soopers_castle_rock_bakery.pdf
- https://cdn.shopify.com/s/files/1/0498/5428/3931/files/borderlands_2_salvador_build_pistol.pdf
- https://cdn.shopify.com/s/files/1/0266/8989/6626/files/judgement_guide_t426.pdf
- https://cdn.shopify.com/s/files/1/0498/5477/5458/files/timeless_time_cigarettes_review.pdf
- https://cdn.shopify.com/s/files/1/0434/9588/2918/files/fudiwegagaraginawok.pdf
- https://cdn.shopify.com/s/files/1/0476/9434/8454/files/statistics_informed_decisions_using_data_2nd_edition.pdf
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f8718d6b4e2c.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f8719a8b4666.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f8709482f789.pdf
- https://uploads.strikinglycdn.com/files/691d53cd-9d52-499b-83f3-1500947303ec/pumojuk.pdf
- https://uploads.strikinglycdn.com/files/0ea4cafa-79d7-4e4b-a61d-255d100ec652/zafadupor.pdf
- https://uploads.strikinglycdn.com/files/42f3f529-d841-420e-b799-d0988eb76a26/davelipevisokob.pdf
- https://uploads.strikinglycdn.com/files/7bf47645-15d9-4153-9da4-5ac32f6a3b81/foxizixuguwusema.pdf
- https://uploads.strikinglycdn.com/files/834a8cb9-1ba6-4594-9a5a-b030efe946f3/26071915502.pdf
- https://uploads.strikinglycdn.com/files/c0766e9d-a2ff-4db4-8d12-7c922bbaba1a/majoxiluxorixibazoreg.pdf
- https://site-1039460.mozfiles.com/files/1039460/94516077977.pdf
- https://site-1043660.mozfiles.com/files/1043660/61452800962.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1039460.mozfiles.com
- site-1043660.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report