SUSPICIOUS — sufojovezonuda.pdf
SUSPICIOUS — sufojovezonuda.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
1a30a1d603d7e6eb6ab12217def5e1972d779380b78c884688e44397a5d042b1 - SHA-1:
86041bf323e60d6524c908e7196b8164a9b66005 - MD5:
dd3401daeeb61cb7afb37f4d0ba68efa - ssdeep:
768:EgGzpDHek+37u7UIVzsi0faIy/xXfdCGJN4hPatSaCVWzZunWwbwRg:xGFze98Z/3vypatSagQYW2mg - TLSH:
T196306DF31097ED8C7A8E6B07ADFB145D5147D38C6132DBA059883A6CD07C6ED6E10A21 - Submitted as: sufojovezonuda.pdf
- File type: pdf · Size: 38965 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=fuel%20gas%20code%20of%20new%20york%20state, https://uploads.strikinglycdn.com/files/5efd67eb-d1af-4dc9-9a82-7177a0de48e8/fajopadal.pdf, https://uploads.strikinglycdn.com/files/8b442b26-6e6f-4348-ac0d-5ec5844eadc8/6651810208.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=fuel%20gas%20code%20of%20new%20york%20state
- https://uploads.strikinglycdn.com/files/5efd67eb-d1af-4dc9-9a82-7177a0de48e8/fajopadal.pdf
- https://uploads.strikinglycdn.com/files/8b442b26-6e6f-4348-ac0d-5ec5844eadc8/6651810208.pdf
- https://uploads.strikinglycdn.com/files/27aef7e9-94da-4360-9abf-4842529bd907/titojaz.pdf
- https://cdn-cms.f-static.net/uploads/4367301/normal_5f885283a7404.pdf
- https://cdn-cms.f-static.net/uploads/4370547/normal_5f88a4da9732a.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f889cd851f78.pdf
- https://cdn.shopify.com/s/files/1/0430/9090/3193/files/14688621070.pdf
- https://cdn.shopify.com/s/files/1/0492/3949/0726/files/google_material_design_android_app.pdf
- https://cdn.shopify.com/s/files/1/0266/8979/8317/files/grade_7_area_and_perimeter_test.pdf
- https://cdn.shopify.com/s/files/1/0483/6347/1001/files/16193793333.pdf
- https://site-1041688.mozfiles.com/files/1041688/somamezojoxe.pdf
- https://site-1038943.mozfiles.com/files/1038943/92538671998.pdf
- https://site-1039380.mozfiles.com/files/1039380/98074851396.pdf
- https://site-1039641.mozfiles.com/files/1039641/5113820807.pdf
- https://site-1040609.mozfiles.com/files/1040609/56398705231.pdf
- https://site-1036719.mozfiles.com/files/1036719/31014695455.pdf
- https://site-1037283.mozfiles.com/files/1037283/jawoxibademenagupokupizax.pdf
- https://site-1040171.mozfiles.com/files/1040171/tolaxupimejujurekukikamo.pdf
- https://site-1042555.mozfiles.com/files/1042555/moruwadenusuwad.pdf
- https://site-1043564.mozfiles.com/files/1043564/41612560401.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f87527021fa7.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f8762debd704.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1041688.mozfiles.com
- site-1038943.mozfiles.com
- site-1039380.mozfiles.com
- site-1039641.mozfiles.com
- site-1040609.mozfiles.com
- site-1036719.mozfiles.com
- site-1037283.mozfiles.com
- site-1040171.mozfiles.com
- site-1042555.mozfiles.com
- site-1043564.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report