SUSPICIOUS — bobanajevija.pdf
SUSPICIOUS — bobanajevija.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6ef772ba0a5d29ca398781c74d6d4f785b9b9f7a4a34ee6760e2953d5bb15368 - SHA-1:
f91edeb647e45a92ec8fc4586adf257cade8b4bb - MD5:
ad9ccf839827b6d660c89f5fda6d9a2b - ssdeep:
768:mgGzpDjpk7AjGTnE0IhyFf4W+S87U/mjqums/ivXV3W5y4cojHq:zGFHpAnE9W+SvujqumASV3W5y4jjHq - TLSH:
T1B5327DF300E7ED4C7A8F9B53ADA725A8A08ED78C7126D75045487B2CC47CAED2E00965 - Submitted as: bobanajevija.pdf
- File type: pdf · Size: 45077 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=fresno%20city%20college%20campus%20map%20pdf, https://cdn-cms.f-static.net/uploads/4368477/normal_5f91916b16de1.pdf, https://cdn-cms.f-static.net/uploads/4365589/normal_5f872b3567ca6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=fresno%20city%20college%20campus%20map%20pdf
- https://cdn-cms.f-static.net/uploads/4368477/normal_5f91916b16de1.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f872b3567ca6.pdf
- https://cdn-cms.f-static.net/uploads/4368477/normal_5f8a678fa7810.pdf
- https://cdn-cms.f-static.net/uploads/4371800/normal_5f8f2b7fecb3b.pdf
- https://uploads.strikinglycdn.com/files/c8de9723-1ad2-4e5e-a605-28845f15d2e9/nudejewuwenaxabupam.pdf
- https://uploads.strikinglycdn.com/files/8846e929-07b1-4f83-bf7a-6f05c8149b27/theodore_boone_kid_lawyer_main_characters.pdf
- https://uploads.strikinglycdn.com/files/2b527817-619d-4a91-9fe8-9a46b39ae8de/24865898935.pdf
- https://uploads.strikinglycdn.com/files/6620b044-8353-448e-95b1-24c6c75cb387/52535110476.pdf
- https://s3.amazonaws.com/zonivezada/pacsun_printable_job_application.pdf
- https://s3.amazonaws.com/sivanira/13306114504.pdf
- https://s3.amazonaws.com/wixamupelinere/16251725381.pdf
- https://uploads.strikinglycdn.com/files/74f3317b-0e9e-498b-b614-751e911f88f5/bingo_game_template_ppt.pdf
- https://uploads.strikinglycdn.com/files/0bd466a2-e590-4677-88ab-2e07a2ef150d/42760913576.pdf
- https://putigazabikikim.weebly.com/uploads/1/3/2/6/132682718/6454644.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/837046.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/3363761.pdf
- https://pivozedotafi.weebly.com/uploads/1/3/1/0/131070355/a7f91e4c9.pdf
- https://rurusoweloxefug.weebly.com/uploads/1/3/3/9/133989150/falawob.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f88b08246894.pdf
- https://cdn-cms.f-static.net/uploads/4383794/normal_5f8e5e7384157.pdf
- https://cdn-cms.f-static.net/uploads/4383571/normal_5f90ebb3a0dc8.pdf
- https://cdn-cms.f-static.net/uploads/4387933/normal_5f90f2f5bfb5e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- putigazabikikim.weebly.com
- bedizegoresupa.weebly.com
- dutitujazekap.weebly.com
- pivozedotafi.weebly.com
- rurusoweloxefug.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report