SUSPICIOUS — bojidijuwodefone.pdf
SUSPICIOUS — bojidijuwodefone.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
22fac5ebf2e1b48274647ee14bb84ceb998614fa8281dd5f72cf7f1051931367 - SHA-1:
db236ddfb596aba5209fe3d7f1dcecdab618d443 - MD5:
d8c9e546b33b74acfaab8b71040723af - ssdeep:
768:RgGzpD2pJdX+b1le23mkdVj70a6nrqWDvHer9oTFhzEgmMNRGIB4QlNUWn:iGFyp9qWk9oLzEgmrkNUWn - TLSH:
T171319DF350A7EC4D7A8A5F539DEB102A5089C7C9A132DBA0489C366CE07C5FD7E109A1 - Submitted as: bojidijuwodefone.pdf
- File type: pdf · Size: 43070 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=powerpoint%20sabbath%20school%20lesson, https://cdn.shopify.com/s/files/1/0428/5811/9334/files/26875959587.pdf, https://cdn.shopify.com/s/files/1/0433/3119/0952/files/gta_vice_city_cheats_psp_flying_cars.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=powerpoint%20sabbath%20school%20lesson
- https://cdn.shopify.com/s/files/1/0428/5811/9334/files/26875959587.pdf
- https://cdn.shopify.com/s/files/1/0433/3119/0952/files/gta_vice_city_cheats_psp_flying_cars.pdf
- https://cdn.shopify.com/s/files/1/0498/6470/4155/files/gemozibupaferiva.pdf
- https://cdn.shopify.com/s/files/1/0498/1384/8219/files/molar_mass_of_potassium_nitrate.pdf
- https://cdn.shopify.com/s/files/1/0496/2595/6505/files/my_life_next_door_movie.pdf
- https://site-1040558.mozfiles.com/files/1040558/2785069614.pdf
- https://site-1043581.mozfiles.com/files/1043581/76121511003.pdf
- https://site-1043080.mozfiles.com/files/1043080/dotenanizij.pdf
- https://cdn.shopify.com/s/files/1/0481/5444/3937/files/prince_of_persia_shadow_and_flame_apk__data.pdf
- https://cdn.shopify.com/s/files/1/0266/9674/5147/files/bliss_kiss_nail_oil_review.pdf
- https://cdn.shopify.com/s/files/1/0432/9357/3288/files/81951492584.pdf
- https://uploads.strikinglycdn.com/files/b48e3b61-4740-48a1-923d-983a292d2aa5/65459756694.pdf
- https://uploads.strikinglycdn.com/files/3ef265a8-e883-4464-ab46-49fa5e23a3f6/gozojinimujudikilepori.pdf
- https://cdn.shopify.com/s/files/1/0481/6997/5965/files/black_ops_2_save_editor_ps3.pdf
- https://cdn.shopify.com/s/files/1/0483/7897/0272/files/74759563659.pdf
- https://cdn.shopify.com/s/files/1/0482/5451/7410/files/9714523396.pdf
- https://cdn.shopify.com/s/files/1/0436/1905/7822/files/15234748758.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f8744f048cc2.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f872b93da47b.pdf
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f876bfc04fbe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1040558.mozfiles.com
- site-1043581.mozfiles.com
- site-1043080.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report