SUSPICIOUS — wemozozililavo_melobitavoz.pdf
SUSPICIOUS — wemozozililavo_melobitavoz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8526c5c03667ef1408628f25b10026bd121716f355e0480d6283c47584f5e1b2 - SHA-1:
0ca1824b2f42ec8a4e0da24021170b929f4e8c16 - MD5:
7935a731b665b96552fe7f70ab1d3e88 - ssdeep:
1536:BGF4pSkQOkwLKzpMToQ//2dAEuHougcd7ySzyjX1KaX0jCN:kF4pEwelMT5/akHoPwySGYjM - TLSH:
T15836AEF710A7EC0C7ECBEF07ACAA2A5A904DDA495172A7504598622CC47C7FE7F40A11 - Submitted as: wemozozililavo_melobitavoz.pdf
- File type: pdf · Size: 69388 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ffxiv%20blu%20masked%20carnival%20guide, https://cdn-cms.f-static.net/uploads/4365659/normal_5f87802de6995.pdf, https://cdn-cms.f-static.net/uploads/4366047/normal_5f87653feb55e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ffxiv%20blu%20masked%20carnival%20guide
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f87802de6995.pdf
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f87653feb55e.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f8710d5af0e6.pdf
- https://site-1037098.mozfiles.com/files/1037098/59455095154.pdf
- https://site-1039378.mozfiles.com/files/1039378/79599520794.pdf
- https://site-1042185.mozfiles.com/files/1042185/2185819111.pdf
- https://site-1039330.mozfiles.com/files/1039330/jinovarinejizebaxix.pdf
- https://uploads.strikinglycdn.com/files/d55e8916-6f33-4c07-8c14-06273d54eeb3/tigezovole.pdf
- https://uploads.strikinglycdn.com/files/ece5dfab-6f15-464b-afdc-bbb6ed4bd4de/309136479.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7304884.pdf
- https://rozolabo.weebly.com/uploads/1/3/0/8/130814594/wujuzidafek-vofux-buxofavewubo.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/novovuxosijuzuz_wofabunutigepuw_dugulelura.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/3722212.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/6003762.pdf
- https://uploads.strikinglycdn.com/files/71cae148-781c-4d75-b863-e16b52e929df/zijures.pdf
- https://uploads.strikinglycdn.com/files/3de8c6b6-a0e8-49f6-9e1a-7c223c8c00b3/81769478156.pdf
- https://uploads.strikinglycdn.com/files/cda60881-8e51-49e2-b635-1bc31fc6b89a/ruxokuzuzapaso.pdf
- https://uploads.strikinglycdn.com/files/88e445c6-7f69-4395-88d9-9c1464ed52b9/87651107367.pdf
- https://uploads.strikinglycdn.com/files/7d433e59-cb53-4789-8497-9d7a04591c9c/pakowa.pdf
- https://cdn.shopify.com/s/files/1/0483/6710/8247/files/swtor_tos_sm_guide.pdf
- https://cdn.shopify.com/s/files/1/0435/3644/9690/files/muvoba.pdf
- https://cdn.shopify.com/s/files/1/0482/2453/4680/files/rev_it_up_reading.pdf
- https://cdn.shopify.com/s/files/1/0434/7189/6741/files/ruwefupugoguban.pdf
- https://cdn.shopify.com/s/files/1/0483/5757/2761/files/gosemixakajodobed.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1037098.mozfiles.com
- site-1039378.mozfiles.com
- site-1042185.mozfiles.com
- site-1039330.mozfiles.com
- uploads.strikinglycdn.com
- genigudepa.weebly.com
- rozolabo.weebly.com
- gimejexoxixaza.weebly.com
- jawasolasazilem.weebly.com
- sibakixode.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report