SUSPICIOUS — midofajewugawapu.pdf
SUSPICIOUS — midofajewugawapu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6abcf28de2d0af1a75eefcaab28a9b91973f0f39b02eef94bea7452dc59b8247 - SHA-1:
8777ebe9dabe7b8f2553dfb163a4271880113a18 - MD5:
3f1144037bb46fc66165f67a0fd6f0d5 - ssdeep:
768:9gGzpD+pzEmnnfQNZ7yYz2ceUv09sWyTAS/E10tPV2W0ev:+GF6pzAs9OxPIW0ev - TLSH:
T12E307BF310A7DD4CBA8B9B436DE71556919AC68C6133E3A008587B6CD4BC6BDBF10860 - Submitted as: midofajewugawapu.pdf
- File type: pdf · Size: 35743 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=lagu%20atikah%20edelweis%20full%20album, https://cdn.shopify.com/s/files/1/0482/0497/2186/files/48237673288.pdf, https://cdn.shopify.com/s/files/1/0500/6327/8238/files/ome_tv_apk_pc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=lagu%20atikah%20edelweis%20full%20album
- https://cdn.shopify.com/s/files/1/0482/0497/2186/files/48237673288.pdf
- https://cdn.shopify.com/s/files/1/0500/6327/8238/files/ome_tv_apk_pc.pdf
- https://cdn.shopify.com/s/files/1/0435/8891/1267/files/57588061671.pdf
- https://cdn.shopify.com/s/files/1/0435/9582/5320/files/99757639725.pdf
- https://site-1043967.mozfiles.com/files/1043967/bobikas.pdf
- https://site-1037079.mozfiles.com/files/1037079/memezatasamubufe.pdf
- https://site-1039491.mozfiles.com/files/1039491/28485600530.pdf
- https://site-1040343.mozfiles.com/files/1040343/23624670302.pdf
- https://site-1037253.mozfiles.com/files/1037253/59311911349.pdf
- https://site-1039253.mozfiles.com/files/1039253/ponadamamerelarabekav.pdf
- https://site-1037920.mozfiles.com/files/1037920/soboka.pdf
- https://site-1040282.mozfiles.com/files/1040282/sajitivutukogebulewurapi.pdf
- https://site-1036694.mozfiles.com/files/1036694/46990519149.pdf
- https://site-1040360.mozfiles.com/files/1040360/bofagipefupug.pdf
- https://site-1043653.mozfiles.com/files/1043653/zumozenafojuvaro.pdf
- https://site-1042787.mozfiles.com/files/1042787/66456178172.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f8775eec33ea.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f8723207e460.pdf
- https://uploads.strikinglycdn.com/files/e041c929-5b49-4eaa-8c19-43b44e8fc2f9/biwegudozikajogor.pdf
- https://uploads.strikinglycdn.com/files/af7256ec-30ab-460a-9382-bf7c3e1c1168/kevitugixudisavagu.pdf
- https://uploads.strikinglycdn.com/files/4274975c-959a-46a5-a765-7a83f3a052b8/29016327566.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1043967.mozfiles.com
- site-1037079.mozfiles.com
- site-1039491.mozfiles.com
- site-1040343.mozfiles.com
- site-1037253.mozfiles.com
- site-1039253.mozfiles.com
- site-1037920.mozfiles.com
- site-1040282.mozfiles.com
- site-1036694.mozfiles.com
- site-1040360.mozfiles.com
- site-1043653.mozfiles.com
- site-1042787.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report