SUSPICIOUS — demugarujujugowebogaso.pdf
SUSPICIOUS — demugarujujugowebogaso.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
23bba01dc89822818bfb9cf3d7517b540c048c8acd57c282f58aef8f336591c5 - SHA-1:
016d98547ebd8fa2196e2766b80ba0f773373f88 - MD5:
50642b23f36f30f59f46b834849a4e80 - ssdeep:
768:sgGzpD0A2psx3L7xTIP2iTeuOeGJUB4tkUJKIFZs5yHEQC8g:pGFolMfx8P264XaUJ5ZsuE58g - TLSH:
T18B33BFF351ABEE8C7A8A6F075EFA2059114AE74C20225AB458C47B2CC47C5BD7F11B60 - Submitted as: demugarujujugowebogaso.pdf
- File type: pdf · Size: 49643 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=confessions+of+an+heiress, https://uploads.strikinglycdn.com/files/d29c38de-781d-4425-88b4-10dc842f0d5f/zatositoxe.pdf, https://uploads.strikinglycdn.com/files/f04cf775-f0af-4d26-86b6-c02f0dffa132/vepebada.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=confessions+of+an+heiress
- https://uploads.strikinglycdn.com/files/d29c38de-781d-4425-88b4-10dc842f0d5f/zatositoxe.pdf
- https://uploads.strikinglycdn.com/files/f04cf775-f0af-4d26-86b6-c02f0dffa132/vepebada.pdf
- https://uploads.strikinglycdn.com/files/aecefee0-0dfb-49a3-b5b8-ead75eefdbc1/73964074053.pdf
- https://uploads.strikinglycdn.com/files/1dc3d6c2-8779-4f57-a2e8-1d627f6dcd9d/45668416735.pdf
- https://site-1036728.mozfiles.com/files/1036728/70402130541.pdf
- https://site-1038634.mozfiles.com/files/1038634/19782506485.pdf
- https://site-1039303.mozfiles.com/files/1039303/98659264708.pdf
- https://site-1038700.mozfiles.com/files/1038700/76793230842.pdf
- https://site-1040871.mozfiles.com/files/1040871/butegufogigepik.pdf
- https://site-1042276.mozfiles.com/files/1042276/11379194001.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036728.mozfiles.com
- site-1038634.mozfiles.com
- site-1039303.mozfiles.com
- site-1038700.mozfiles.com
- site-1040871.mozfiles.com
- site-1042276.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report