SUSPICIOUS — pizemob.pdf
SUSPICIOUS — pizemob.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9545e07bc48e09775415e89610bcc8e94cfc5f48a8c54f7e1b63776d2c2f6918 - SHA-1:
03990be6459f9377abd7883be3423bc2fbdf8a33 - MD5:
b546bfff406c7f10ebe5d1874b6cfa95 - ssdeep:
768:sgGzpDFpc1u6sNpCi62XOihlBakP+L0axUOaR1wCbg8l0wGl:pGFBpRei7B9+LNxUOaR19l0wGl - TLSH:
T1FA317CF310D7ED8D7A87AB43ADB72659118AC7887126D7A0488C732DD4FC66DBE10860 - Submitted as: pizemob.pdf
- File type: pdf · Size: 42937 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=salesforce%20data%20download%20log, https://cdn.shopify.com/s/files/1/0496/7038/9924/files/human_connection_with_connect_6th_edition.pdf, https://cdn.shopify.com/s/files/1/0435/5915/7921/files/level_up_dnd_5e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=salesforce%20data%20download%20log
- https://cdn.shopify.com/s/files/1/0496/7038/9924/files/human_connection_with_connect_6th_edition.pdf
- https://cdn.shopify.com/s/files/1/0435/5915/7921/files/level_up_dnd_5e.pdf
- https://cdn.shopify.com/s/files/1/0483/0504/5659/files/foruva.pdf
- https://cdn.shopify.com/s/files/1/0485/2364/0987/files/88635982602.pdf
- https://uploads.strikinglycdn.com/files/f33bb21b-a9e2-44e2-a806-8e7502b89f9c/nivabipedamafosi.pdf
- https://uploads.strikinglycdn.com/files/38125f20-ce70-4817-9dd8-a20131d3257e/sobepibazagewizav.pdf
- https://uploads.strikinglycdn.com/files/48cb4fab-2bdf-4f69-97e4-11abf2e3fe06/sirafejaribul.pdf
- https://uploads.strikinglycdn.com/files/caabac7f-4158-486e-a359-e7f34280670a/rubopi.pdf
- https://uploads.strikinglycdn.com/files/8c9533ac-c597-4082-b829-8fa1758bd782/882494644.pdf
- https://uploads.strikinglycdn.com/files/54f5bcd9-c409-417d-8e86-9fc943ff20c5/jakipekodoguwel.pdf
- https://uploads.strikinglycdn.com/files/8e626d40-b658-4252-b272-344fa5d39cd8/tatopoganidivamino.pdf
- https://uploads.strikinglycdn.com/files/6e224474-da88-4935-af45-6b109dbb20c7/mavitozerebaxofep.pdf
- https://uploads.strikinglycdn.com/files/9346b5be-cf4b-4c90-9410-55f2a91cba07/jadanunemofabewotigamaso.pdf
- https://uploads.strikinglycdn.com/files/8999cca3-ac49-4020-a2ad-9124d70c5bf5/xusozovavu.pdf
- https://site-1039514.mozfiles.com/files/1039514/rejarodat.pdf
- https://site-1043771.mozfiles.com/files/1043771/nozorezijojok.pdf
- https://site-1042971.mozfiles.com/files/1042971/40440753143.pdf
- https://site-1037835.mozfiles.com/files/1037835/bedifilelalaxasif.pdf
- https://cdn-cms.f-static.net/uploads/4370746/normal_5f88dc62d072c.pdf
- https://cdn-cms.f-static.net/uploads/4367642/normal_5f87578b60a28.pdf
- https://uploads.strikinglycdn.com/files/5db716f7-8c60-48a2-8ea5-4e4df648b1a1/joxujemarifisaj.pdf
- https://uploads.strikinglycdn.com/files/3ca3385c-4e33-46e6-8311-011fc3263930/74819671266.pdf
- https://uploads.strikinglycdn.com/files/6c9829f4-5d8b-4792-a7e1-9876bf6b6dd8/dowagafepujez.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039514.mozfiles.com
- site-1043771.mozfiles.com
- site-1042971.mozfiles.com
- site-1037835.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report