SUSPICIOUS — bipozitefema.pdf
SUSPICIOUS — bipozitefema.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
5e409c157d19162d31d32943035cee9240db6cdfe2f2ff8d2be3979c21a1b202 - SHA-1:
45fed8b86018151da04ee5dd6071bf516da7b808 - MD5:
c6b16cddf56352075664225e3806715d - ssdeep:
768:dgGzpDGpQDm32/6rlLaYYL+rgWL1dzP/X5bn+uykgsEAhE+1:eGF6pI2gWLbzXXpn+fvAhE+1 - TLSH:
T105306BF324D7EC4C7A8BAB139DB715A9508DC2486237D7A0588C7B2DD4BC6AD7E10860 - Submitted as: bipozitefema.pdf
- File type: pdf · Size: 36058 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=gameshark%20iso%20ps2, https://site-1038925.mozfiles.com/files/1038925/nozujikumuros.pdf, https://site-1038844.mozfiles.com/files/1038844/1100049475.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=gameshark%20iso%20ps2
- https://site-1038925.mozfiles.com/files/1038925/nozujikumuros.pdf
- https://site-1038844.mozfiles.com/files/1038844/1100049475.pdf
- https://site-1042347.mozfiles.com/files/1042347/fokofawoxunibiwe.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f870af8ba56b.pdf
- https://cdn-cms.f-static.net/uploads/4367289/normal_5f8751ddb12a1.pdf
- https://cdn-cms.f-static.net/uploads/4367916/normal_5f876a571c69c.pdf
- https://cdn-cms.f-static.net/uploads/4367277/normal_5f87658cb0dcd.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f876bda53c26.pdf
- https://uploads.strikinglycdn.com/files/552bc072-9a97-404b-b423-7ea2b176ab9b/vatelajokiditoruzudozonup.pdf
- https://uploads.strikinglycdn.com/files/85f72356-8b5e-417d-9456-0815fb00b96d/8394213410.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f8758651310a.pdf
- https://cdn-cms.f-static.net/uploads/4366989/normal_5f876acedd1d7.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f876c8c93ae1.pdf
- https://cdn-cms.f-static.net/uploads/4367944/normal_5f876ef671bc4.pdf
- https://cdn-cms.f-static.net/uploads/4367903/normal_5f87676c18906.pdf
- https://uploads.strikinglycdn.com/files/943eb1df-cb01-417b-a38d-76fe98093a02/fitokavizox.pdf
- https://uploads.strikinglycdn.com/files/32497417-39fe-48f4-b4a7-64fe5adea2d8/bunajolojigadopejizaxuti.pdf
- https://uploads.strikinglycdn.com/files/58bff6e9-70d4-46cd-a418-a1fbad951005/nixitamumed.pdf
- https://uploads.strikinglycdn.com/files/76ec9063-bcc9-4086-95fa-caf78450c9af/belefoxomopoxuz.pdf
- https://uploads.strikinglycdn.com/files/063a4aa0-608d-4b1b-8210-234210ce66c0/6726265452.pdf
- https://uploads.strikinglycdn.com/files/7a2e92b6-2239-4afc-b983-a757fc9fce8f/14861377931.pdf
- https://uploads.strikinglycdn.com/files/50342610-3326-4206-9702-938cde9001a5/bufejebepibixusoxigilim.pdf
- https://uploads.strikinglycdn.com/files/8a4df425-f7e0-49bf-a46b-b43f0eed4e22/guwadufewaxoxamuboko.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- site-1038925.mozfiles.com
- site-1038844.mozfiles.com
- site-1042347.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report