SUSPICIOUS — tusudovimejab.pdf
SUSPICIOUS — tusudovimejab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
450370b8b4dda7535be1b82d42738eaaeba55e6214bc9eab6cf50bbdcb261d0c - SHA-1:
7dce9d877b400694997b6f95ecc6437fefae7c2f - MD5:
a19c7d7a2b9102e919a884c5d18d4338 - ssdeep:
768:ygGzpDKgFA+VJYKoJorRaC5VXAdw+QDSTpw5:vGFmRK75NA23WK5 - TLSH:
T1C0308CF350ABDD8DB6869B076EFA0109614AC789A133D2B014DC3B6CC4BC6BD7E05861 - Submitted as: tusudovimejab.pdf
- File type: pdf · Size: 35813 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=expanded%20noun%20phrases%20worksheet, https://uploads.strikinglycdn.com/files/eef625aa-eee4-45a6-bc62-fb4295f13bd8/dishwasher_not_cleaning_well_bosch.pdf, https://cdn-cms.f-static.net/uploads/4374540/normal_5f8f9fd300138.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=expanded%20noun%20phrases%20worksheet
- https://uploads.strikinglycdn.com/files/eef625aa-eee4-45a6-bc62-fb4295f13bd8/dishwasher_not_cleaning_well_bosch.pdf
- https://cdn-cms.f-static.net/uploads/4374540/normal_5f8f9fd300138.pdf
- https://uploads.strikinglycdn.com/files/480689a2-d5f7-4975-a424-683358e7a068/71256274338.pdf
- https://uploads.strikinglycdn.com/files/c7c35c63-8ffa-49ef-8d4a-08f67fe803ab/92509489076.pdf
- https://uploads.strikinglycdn.com/files/405dc20d-2613-43ef-b67a-aefae50e9724/wonikumifodukiwanixafuwe.pdf
- https://cdn-cms.f-static.net/uploads/4366961/normal_5f8c42ff5f90b.pdf
- https://uploads.strikinglycdn.com/files/0e883af7-e6b8-4933-bc6a-af3df2728a20/best_55_inch_4k_tv_canada.pdf
- https://uploads.strikinglycdn.com/files/e755f36d-a879-4ca9-b9cd-c47ba972ef3d/vunomokuvepowamokopa.pdf
- https://uploads.strikinglycdn.com/files/5145bad0-3050-4455-a691-b66735b9e63e/15413385973.pdf
- https://uploads.strikinglycdn.com/files/c210b487-d791-4872-b9dc-c0801a52dcaa/test_de_logique_concours.pdf
- https://uploads.strikinglycdn.com/files/b8bd68ba-8179-4444-9497-4e0059bb0777/zitifatibukidasener.pdf
- https://cdn-cms.f-static.net/uploads/4388163/normal_5f93f122e5bb2.pdf
- https://cdn-cms.f-static.net/uploads/4425768/normal_5f98a5bd2982a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report