SUSPICIOUS — mobafewod.pdf
SUSPICIOUS — mobafewod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4e673c8da44409f80a39d4f68a2785f16fce33e86b742db3aed72904fab28e01 - SHA-1:
ef63272bada5bee3815d15ef612ee49dccdedc63 - MD5:
7da62ed0b554684de1a92f06c67f8c2b - ssdeep:
768:ggGzpDbp8kqJcMzQe3CngocLMogw4hyvQ5WJ6hPlJv+ggFabSYbNn10:tGFfpF4bgwOtPlJv+RFabJn10 - TLSH:
T169327CF310A7ED4CBB4B6B43AEAA1169A245D74CA137D79044C8267CC4BC6FD6F10A12 - Submitted as: mobafewod.pdf
- File type: pdf · Size: 44010 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=bookworm%20adventures%20deluxe%20crack, https://site-1039303.mozfiles.com/files/1039303/48908049686.pdf, https://site-1048535.mozfiles.com/files/1048535/benefits_of_vegetarianism.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=bookworm%20adventures%20deluxe%20crack
- https://site-1039303.mozfiles.com/files/1039303/48908049686.pdf
- https://site-1048535.mozfiles.com/files/1048535/benefits_of_vegetarianism.pdf
- https://site-1044192.mozfiles.com/files/1044192/dorot.pdf
- https://cdn.shopify.com/s/files/1/0483/8110/0183/files/pathfinder_ranger_archer_build.pdf
- https://cdn.shopify.com/s/files/1/0483/4780/7895/files/jizaxepolozidipeluki.pdf
- https://cdn.shopify.com/s/files/1/0266/7711/7125/files/xelunevebevowom.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f877ad318e70.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f87690bd3d5e.pdf
- https://cdn.shopify.com/s/files/1/0484/7203/1382/files/akribos_xxiv_watches_price_in_india.pdf
- https://cdn.shopify.com/s/files/1/0502/2983/7982/files/poudre_school_district_staff_calendar.pdf
- https://cdn.shopify.com/s/files/1/0486/5074/8062/files/othello_study_guide_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0499/4996/6485/files/95912011546.pdf
- https://cdn.shopify.com/s/files/1/0433/9938/1159/files/bop_magazine_90s.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/bewomo.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/d51091c6dd1f.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/40ddfa4d7f4e3e.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/f9007.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/mafezoluruzowez.pdf
- https://cdn-cms.f-static.net/uploads/4366316/normal_5f873003e0a02.pdf
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f877bcbe939f.pdf
- https://cdn-cms.f-static.net/uploads/4366309/normal_5f8761ede0179.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- site-1039303.mozfiles.com
- site-1048535.mozfiles.com
- site-1044192.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- bedizegoresupa.weebly.com
- jeponiruwapin.weebly.com
- mogilifus.weebly.com
- dutitujazekap.weebly.com
- fadusoga.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report