SUSPICIOUS — bonemezukogedit-pawobelibepilev-pevive-bironofugave.pdf
SUSPICIOUS — bonemezukogedit-pawobelibepilev-pevive-bironofugave.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
32eb22998ed36af7888d838586d4c1d07e7d2af24c55bd14da3c146c7cfc4d01 - SHA-1:
2968504bde7a9307b9a421092944336b81894b17 - MD5:
545f36329aad18b81725ca3ed1281177 - ssdeep:
768:JgGzpDtpUs2JA9IrII8IHa6vI+sX5ZO1hkli+AdE4UOODCrISy9cyatfP2Yksja:qGFhpD6vI+sXOeAdWKIEyaNP2Yk4a - TLSH:
T19A32BFF3509BEC8D768ADB07ADAA2454159CD3886133D7A459CC372CC0BC2BD6F90962 - Submitted as: bonemezukogedit-pawobelibepilev-pevive-bironofugave.pdf
- File type: pdf · Size: 46285 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ielts%20reading%20answer%20key%20pdf, https://uploads.strikinglycdn.com/files/3dcb7b0c-7620-4c6c-ae5c-8e8788b015f5/33419917605.pdf, https://uploads.strikinglycdn.com/files/f39a14fc-28d7-4de5-8291-a55c9e64fed7/11172627395.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ielts%20reading%20answer%20key%20pdf
- https://uploads.strikinglycdn.com/files/3dcb7b0c-7620-4c6c-ae5c-8e8788b015f5/33419917605.pdf
- https://uploads.strikinglycdn.com/files/f39a14fc-28d7-4de5-8291-a55c9e64fed7/11172627395.pdf
- https://uploads.strikinglycdn.com/files/95b5e966-6f2a-4d1c-9385-9bd9927d8f4b/26785829690.pdf
- https://site-1038789.mozfiles.com/files/1038789/55941439670.pdf
- https://site-1038995.mozfiles.com/files/1038995/93695980960.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f878c7bb3b41.pdf
- https://cdn-cms.f-static.net/uploads/4368487/normal_5f87e616cde43.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f872e1e83482.pdf
- https://cdn-cms.f-static.net/uploads/4368242/normal_5f87809069031.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f8741384cd16.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f87d72259d95.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f8765dd81f90.pdf
- https://cdn.shopify.com/s/files/1/0487/7248/1190/files/mcculloch_v._maryland_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0431/9268/0611/files/minecraft_mods_1.6.4.pdf
- https://cdn.shopify.com/s/files/1/0492/0888/5414/files/wenezofogozisow.pdf
- https://cdn.shopify.com/s/files/1/0501/6918/4421/files/ecological_pyramid_worksheet_page_25_answers.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/alamosa_high_school_yearbook.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1038789.mozfiles.com
- site-1038995.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report