SUSPICIOUS — 8501393.pdf
SUSPICIOUS — 8501393.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7472bda67b3584f839d9c488bd344f35dd7f35d7767ae2ecccb7b91ce545dfd6 - SHA-1:
05afbe261593a2e712abeafb457d1f55e9bab691 - MD5:
3f37f384082601e95f2dd65153dd8457 - ssdeep:
768:JgGzpDMphvbFlG8l2QERuL+GbxA5AtV/VwngvkrXS/Q/14xHDs0tyw:qGFQphZpmqrkrmLHDsg5 - TLSH:
T1C7318DF36097EC4C3B8B9F13AAEA0599A08DC7CD6127D7A01098772CC4BC6ED2E10955 - Submitted as: 8501393.pdf
- File type: pdf · Size: 40265 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=call%20of%20warhammer%20botet%20guide, https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/gozimipowiwirov_lagisi_wexalanexepelem.pdf, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/ruxozukozuvazu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=call%20of%20warhammer%20botet%20guide
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/gozimipowiwirov_lagisi_wexalanexepelem.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/ruxozukozuvazu.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/runemevurexuziwone.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/9276785.pdf
- https://cdn-cms.f-static.net/uploads/4373778/normal_5f88f3f3a6fb4.pdf
- https://uploads.strikinglycdn.com/files/f8f2f06e-2e65-43a9-846e-a787045fc8c9/pavekobasovifodoxo.pdf
- https://uploads.strikinglycdn.com/files/5df66f1b-8b17-4c00-a8eb-b618c465d51c/48011673357.pdf
- https://uploads.strikinglycdn.com/files/4c88b475-3d01-4d4a-adc0-1abb7bca9912/sisugelebos.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/41b2e61717b.pdf
- https://besavikeneg.weebly.com/uploads/1/3/2/8/132815808/21e75.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/goxonarimuvi_vowunepe_lutofuzadugike.pdf
- https://cdn-cms.f-static.net/uploads/4368238/normal_5f87e8a907061.pdf
- https://cdn-cms.f-static.net/uploads/4369765/normal_5f88bc1d3053b.pdf
- https://cdn-cms.f-static.net/uploads/4370073/normal_5f88bd9c78fd2.pdf
- https://cdn-cms.f-static.net/uploads/4370088/normal_5f890092772e0.pdf
- https://cdn-cms.f-static.net/uploads/4368506/normal_5f885d38c5cc8.pdf
- https://cdn-cms.f-static.net/uploads/4368230/normal_5f87a3bd24462.pdf
- https://cdn-cms.f-static.net/uploads/4369182/normal_5f893357e32fd.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f86fc97ae326.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- boguvetasitob.weebly.com
- jatorogerujew.weebly.com
- genigudepa.weebly.com
- dutitujazekap.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- wetuxabo.weebly.com
- besavikeneg.weebly.com
- xawuwotogot.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report