SUSPICIOUS — mijusid.pdf
SUSPICIOUS — mijusid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
6832f6fb59f554b5c0333d9c87e0736432f30d54641e7be2798966c1a083bae4 - SHA-1:
66e103bf9da551dbaf3b9ecbb30322d0fea2099f - MD5:
cb5c54a1ab7b11aa5020a86964d3b33f - ssdeep:
768:hjgGzpD4BWlupmhwdL17C1BG0Fx0kIB2SOxMirzhAPeZGn3xfzIBJUtayavn2:KGF081Q0XJfbhAPeZG3xk4ta7vn2 - TLSH:
T1A131AEF3515BFD8DBECA8B0379662465394AC38CB1379A5419CC3A6CC4BC6BC6E00961 - Submitted as: mijusid.pdf
- File type: pdf · Size: 43156 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=conceptual%20chemistry%205th%20edition%20pdf, https://cdn-cms.f-static.net/uploads/4401518/normal_5fa5304089a94.pdf, https://cdn-cms.f-static.net/uploads/4372073/normal_5f96a0e5c8ea4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=conceptual%20chemistry%205th%20edition%20pdf
- https://cdn-cms.f-static.net/uploads/4401518/normal_5fa5304089a94.pdf
- https://cdn-cms.f-static.net/uploads/4372073/normal_5f96a0e5c8ea4.pdf
- https://s3.amazonaws.com/sazariwapa/canvas_sweetwater_schools_login.pdf
- https://cdn-cms.f-static.net/uploads/4418972/normal_5f9e75d89e467.pdf
- https://cdn-cms.f-static.net/uploads/4449405/normal_5fa55a09e707e.pdf
- https://s3.amazonaws.com/jukoxisojow/who_is_presiding_officer_of_the_house_of_representatives.pdf
- https://cdn-cms.f-static.net/uploads/4376120/normal_5f89d5a478ef4.pdf
- https://cdn-cms.f-static.net/uploads/4386094/normal_5f934765cc0db.pdf
- https://s3.amazonaws.com/muvemasoxaji/canada_post_envelope_regulations.pdf
- https://uploads.strikinglycdn.com/files/5573a79f-0aa4-48e0-9455-18cbdd20472f/tezeloxojak.pdf
- https://s3.amazonaws.com/wofaxil/biological_classification_class_11_mcq.pdf
- https://dejubanev.files.wordpress.com/2020/11/ziwibu.pdf
- https://s3.amazonaws.com/lupuvogotog/kuziw.pdf
- https://s3.amazonaws.com/pazifetanegapu/dagopeg.pdf
- https://cdn-cms.f-static.net/uploads/4405930/normal_5f9da23ee167f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- dejubanev.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report