SUSPICIOUS — lovaximavok_zudapopi.pdf
SUSPICIOUS — lovaximavok_zudapopi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
60fcb9f9b466a89b8a86d028eabaf9635e9054016a69a34a09134938fbf736b5 - SHA-1:
694eec2556f1192b690940908800a967bb8b5610 - MD5:
345edb144404419ede9a7031379e031e - ssdeep:
768:8gGzpDZ3p2mcEXtcYLPABelFOlCx+g/QdF65+hLihiOrcy64oPg9naBV:ZGFxpmQP5/QdF6QtOrhuPg9naBV - TLSH:
T1572F7DF3509BEC8C7A8B9B137CEB256A5059C74D2132E7A00A88276CD5BC6BD7F00950 - Submitted as: lovaximavok_zudapopi.pdf
- File type: pdf · Size: 32624 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=jinglebell%20rock%20sheet%20music, https://cdn.shopify.com/s/files/1/0481/1882/5123/files/route_2_pokemon_sun.pdf, https://cdn.shopify.com/s/files/1/0497/5581/6090/files/flip_master_unblocked.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=jinglebell%20rock%20sheet%20music
- https://cdn.shopify.com/s/files/1/0481/1882/5123/files/route_2_pokemon_sun.pdf
- https://cdn.shopify.com/s/files/1/0497/5581/6090/files/flip_master_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0428/4927/1975/files/barbie_cooking_show.pdf
- https://uploads.strikinglycdn.com/files/014f5be6-dc81-43ec-82be-4cde72a0c45d/30231220891.pdf
- https://cdn.shopify.com/s/files/1/0501/1580/5349/files/falevitamabeko.pdf
- https://cdn.shopify.com/s/files/1/0432/6214/8763/files/rabebexesavokowaza.pdf
- https://cdn.shopify.com/s/files/1/0476/7793/1686/files/identify_the_controls_and_variables_simpsons_answers.pdf
- https://cdn.shopify.com/s/files/1/0487/7451/2806/files/4776462192.pdf
- https://cdn.shopify.com/s/files/1/0495/9846/4152/files/sensation_and_perception_2nd_edition_yantis.pdf
- https://uploads.strikinglycdn.com/files/bfd729ca-bb50-4e7a-bee2-044959a33771/8639277177.pdf
- https://uploads.strikinglycdn.com/files/f71a2d24-4b40-4c6f-ba96-c771b227483f/watekapawejafavojegiwe.pdf
- https://site-1039689.mozfiles.com/files/1039689/podap.pdf
- https://site-1048224.mozfiles.com/files/1048224/95460107504.pdf
- https://site-1039848.mozfiles.com/files/1039848/vazexukile.pdf
- https://cdn.shopify.com/s/files/1/0486/5002/7176/files/zofigutolavuvomagoneg.pdf
- https://cdn.shopify.com/s/files/1/0437/4256/0407/files/warhammer_40k_weapons_1d4chan.pdf
- https://cdn.shopify.com/s/files/1/0434/3300/1126/files/shadowrun_5e_cyberware_grades.pdf
- https://cdn.shopify.com/s/files/1/0498/6735/8363/files/booster_pac_es2500_user_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039689.mozfiles.com
- site-1048224.mozfiles.com
- site-1039848.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report