SUSPICIOUS — bonogisupu.pdf
SUSPICIOUS — bonogisupu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
19b6e5513af269f2877edf121354abc6bc1a05b28e9280d03e9ebf311cedc1a3 - SHA-1:
41b4fbf12b998e5d5c7eee3f4b846cfd9a52ecea - MD5:
b65dc60171e1c12220df18d6a1de7db7 - ssdeep:
1536:bGF8pdIfflYHcc8sUQg85obqCfRIDW5uPgqH7:6F8pdif6V8s+8+bqsKEs - TLSH:
T19635AFF350D7DD8CBACBAF03AEBA1158A04ED7493172939054983B5DD4BC9ED2E00A61 - Submitted as: bonogisupu.pdf
- File type: pdf · Size: 60723 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=card%20magic%20tricks%20pdf, https://uploads.strikinglycdn.com/files/9888f8b1-e869-40a4-8cbf-6f666bb4dc03/zosumowazadidilugu.pdf, https://uploads.strikinglycdn.com/files/69a5faaf-1219-4dc1-9c6b-38d2b67fb7b2/guwivogibevigut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: additional-actions, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=card%20magic%20tricks%20pdf
- https://uploads.strikinglycdn.com/files/9888f8b1-e869-40a4-8cbf-6f666bb4dc03/zosumowazadidilugu.pdf
- https://uploads.strikinglycdn.com/files/69a5faaf-1219-4dc1-9c6b-38d2b67fb7b2/guwivogibevigut.pdf
- https://uploads.strikinglycdn.com/files/564c1553-db12-4404-84bb-5621fbcfd8a9/pedijofapulore.pdf
- https://uploads.strikinglycdn.com/files/d131e733-ff0b-4c37-861d-fc381c7f3d6e/momokebu.pdf
- https://uploads.strikinglycdn.com/files/bbb79fc2-e8bf-48ba-9b65-2bd16ac82914/45402921357.pdf
- https://site-1043908.mozfiles.com/files/1043908/20020269952.pdf
- https://cdn.shopify.com/s/files/1/0439/5902/5822/files/33605308993.pdf
- https://cdn.shopify.com/s/files/1/0494/3288/7463/files/sugilo.pdf
- https://cdn.shopify.com/s/files/1/0484/4784/8602/files/61580199344.pdf
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f87bf1e98f2f.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f8723ef9bb70.pdf
- https://cdn-cms.f-static.net/uploads/4366408/normal_5f871d34ddb51.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f878a740cd24.pdf
- https://uploads.strikinglycdn.com/files/d551629d-1f0f-4a11-ad7b-6a75bcb54d9b/50929440849.pdf
- https://uploads.strikinglycdn.com/files/0def4ea3-f900-4b94-af75-54f58f8b04bc/47998590735.pdf
- https://uploads.strikinglycdn.com/files/a966113f-fe88-4692-bf40-ed6ae6770fbe/12674428927.pdf
- https://uploads.strikinglycdn.com/files/1c74a163-3942-4eb4-8a61-f1a23e3a9e2d/57111655135.pdf
- https://uploads.strikinglycdn.com/files/685fac61-6bab-4497-9638-b6bc381e6fec/dekire.pdf
- https://site-1037022.mozfiles.com/files/1037022/57952712912.pdf
- https://site-1043195.mozfiles.com/files/1043195/13582999456.pdf
- https://site-1038605.mozfiles.com/files/1038605/muwutedux.pdf
- https://site-1040669.mozfiles.com/files/1040669/29175414343.pdf
- https://site-1040200.mozfiles.com/files/1040200/99737259377.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1043908.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1037022.mozfiles.com
- site-1043195.mozfiles.com
- site-1038605.mozfiles.com
- site-1040669.mozfiles.com
- site-1040200.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report