SUSPICIOUS — momumodesawofomosaj.pdf
SUSPICIOUS — momumodesawofomosaj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
509d24fe2921aa38f96c5624621aa272434daaf8a93228bc953a1b91ba51d5a4 - SHA-1:
7d3aa67972cf5eaeb46e649286d3a6947eccf71c - MD5:
676ed40595401ddbb3e623cf5800ca60 - ssdeep:
768:rgGzpDClDqrnZNqKlAIRtOZaH1fQ4KhIHXNoro+pf7aAu7fWxfk5uyWelNMH:UGFmMrn4mHXCrJPOfwNelNMH - TLSH:
T12E329DF310A7ED4C7A879B43ADAF295D9649D78C9032E2605598372CC1783BDBE50A20 - Submitted as: momumodesawofomosaj.pdf
- File type: pdf · Size: 46306 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=icodis%20projector%20manual, https://cdn-cms.f-static.net/uploads/4366359/normal_5f889e822a4be.pdf, https://cdn-cms.f-static.net/uploads/4368219/normal_5f87a4676a913.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=icodis%20projector%20manual
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f889e822a4be.pdf
- https://cdn-cms.f-static.net/uploads/4368219/normal_5f87a4676a913.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f87bf2c3b98e.pdf
- https://cdn-cms.f-static.net/uploads/4392220/normal_5f9350bb7cb05.pdf
- https://cdn.shopify.com/s/files/1/0430/9506/4733/files/vexenimexuxepuxokunenu.pdf
- https://cdn.shopify.com/s/files/1/0479/6445/5079/files/monatliche_lohnsteuer_2020.pdf
- https://cdn.shopify.com/s/files/1/0433/6828/4316/files/mifid_ii_directive.pdf
- https://cdn.shopify.com/s/files/1/0502/2393/9753/files/gmail_android_app_message_queued.pdf
- https://cdn.shopify.com/s/files/1/0494/7735/3639/files/76437564063.pdf
- https://cdn.shopify.com/s/files/1/0433/7808/1959/files/figury_paskie_sprawdzian_3_gimnazjum.pdf
- https://cdn.shopify.com/s/files/1/0436/1669/8526/files/1542192766.pdf
- https://cdn.shopify.com/s/files/1/0483/9440/4008/files/3-3_linear_programming_worksheet_with_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0500/8277/5212/files/bajonenudesejigagedofa.pdf
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/tumuxalegirisakenig.pdf
- https://cdn.shopify.com/s/files/1/0497/5978/1023/files/chopin_piano_nocturne.pdf
- https://s3.amazonaws.com/pisedij/24553372441.pdf
- https://s3.amazonaws.com/tetazino/data_acquisition_card.pdf
- https://s3.amazonaws.com/zirojopemup/5238373282.pdf
- https://s3.amazonaws.com/davawina/37141885449.pdf
- https://uploads.strikinglycdn.com/files/640411ab-8b6d-4773-9373-ce792d6ed5ad/wisefa.pdf
- https://uploads.strikinglycdn.com/files/0fe68002-4f00-4492-b672-9201153f6647/32386881437.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report