SUSPICIOUS — mogugotute.pdf
SUSPICIOUS — mogugotute.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
49998e53cb9cc0b0ed76410b49c3bfa20b580d082a29ecf09e4055b82698801d - SHA-1:
9f80644dd413c0c92fa9d578703ca3a69f3cc0fa - MD5:
3f643a3403fd927f0c9f647205226039 - ssdeep:
3072:8Fdp150k2RenuvdV2dZWVs3KJ7oDK/g9+79rLjWSio56/8bMf:0f150k2yEmd4Vs3W7oO/g9kNL625Yn - TLSH:
T1283FF1F71C5BEE8E7649EB03EB911116A94CC64C6621DB9046E47E2DD07C2FC3E118A1 - Submitted as: mogugotute.pdf
- File type: pdf · Size: 154845 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ghostscript%20combine%20pdf%20pages, https://cdn.shopify.com/s/files/1/0462/0150/3897/files/mendenhall_high_school_yearbook.pdf, https://cdn.shopify.com/s/files/1/0431/3487/7850/files/frog_dissection_guide.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ghostscript%20combine%20pdf%20pages
- https://cdn.shopify.com/s/files/1/0462/0150/3897/files/mendenhall_high_school_yearbook.pdf
- https://cdn.shopify.com/s/files/1/0431/3487/7850/files/frog_dissection_guide.pdf
- https://cdn.shopify.com/s/files/1/0434/0681/9493/files/mozisijikufawuj.pdf
- https://cdn.shopify.com/s/files/1/0498/0483/7018/files/688_credit_score_good_or_bad.pdf
- https://cdn.shopify.com/s/files/1/0504/0698/1830/files/aua_guideline_2020_bph.pdf
- https://cdn.shopify.com/s/files/1/0484/6996/7013/files/12626138923.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f87520773ccc.pdf
- https://cdn-cms.f-static.net/uploads/4369917/normal_5f8ee60fa22d4.pdf
- https://cdn-cms.f-static.net/uploads/4401518/normal_5f9172f0a1b21.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f8737b756892.pdf
- https://cdn-cms.f-static.net/uploads/4374703/normal_5f8f3d7dbaed1.pdf
- https://jobugatiponez.weebly.com/uploads/1/3/4/2/134234820/ziwanifujisavito.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/bdfa22f.pdf
- https://uploads.strikinglycdn.com/files/9eefce28-cba7-4810-a3d1-62f94481c9f2/91507019995.pdf
- https://uploads.strikinglycdn.com/files/577d5082-6858-4f56-8c44-0f1451ba0936/98328105188.pdf
- https://uploads.strikinglycdn.com/files/db9f4d04-8bd3-464b-b0de-a994f26f9c9f/dodge_ram_6_speed_manual_transmission_problems.pdf
- https://uploads.strikinglycdn.com/files/aed168ed-7759-4f43-991c-5158ecd4a7f1/95407402424.pdf
- https://uploads.strikinglycdn.com/files/6a4c5d07-cc9f-4fd5-8355-81d6a43e42dd/76605401654.pdf
- https://uploads.strikinglycdn.com/files/854b9a67-4963-4fc0-bf2b-0b1acb127729/lonefuzitepiribalabob.pdf
- https://uploads.strikinglycdn.com/files/b85192a9-5bce-4d80-8b9b-43755e876f09/rubuligugizesoluxugamef.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- jobugatiponez.weebly.com
- jaserasozupog.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report