SUSPICIOUS — bepabamalugokovagojigitul.pdf
SUSPICIOUS — bepabamalugokovagojigitul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
a42f15f88cb66ca6a2ea4a2ed5ec7a73e4c29368e28bbf1b96b5fff2eaf510de - SHA-1:
53a7fd65826bc3649a57e81dd5a3b26778cfd1e7 - MD5:
251d05c59daa6f49a4c30337b19a089f - ssdeep:
1536:6GFNHe+54iEefYhPxikKmA1e6/jhbWdpx5spj6Y/ru:jFNHeregnqh/jhSpHspj6Y6 - TLSH:
T1CF36CFF3556BDE4C624BA743E8E62598604AC38C6176A76058D87B3EC8FC6FC2F50940 - Submitted as: bepabamalugokovagojigitul.pdf
- File type: pdf · Size: 65380 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=chiropractic+adjustment+methods, https://uploads.strikinglycdn.com/files/76eb9a3f-f215-4bac-88f1-7fe8f7e980c5/kivigegabepesapuneg.pdf, https://uploads.strikinglycdn.com/files/8563adee-2a89-4bf0-b661-139f87465ecd/1420931696.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=chiropractic+adjustment+methods
- https://uploads.strikinglycdn.com/files/76eb9a3f-f215-4bac-88f1-7fe8f7e980c5/kivigegabepesapuneg.pdf
- https://uploads.strikinglycdn.com/files/8563adee-2a89-4bf0-b661-139f87465ecd/1420931696.pdf
- https://uploads.strikinglycdn.com/files/7893d9c1-c295-4d80-b259-08c378dab5e1/57729996517.pdf
- https://uploads.strikinglycdn.com/files/7db20465-e341-4de9-a1ca-5f9a203b142e/64921983810.pdf
- https://uploads.strikinglycdn.com/files/2d407ed3-dfa9-45fb-8290-6cbdbe56040f/mutaxiramexixokuf.pdf
- https://uploads.strikinglycdn.com/files/6cf94822-a654-475b-a465-cfe34a61f960/11761246428.pdf
- https://uploads.strikinglycdn.com/files/f4ca5b40-394f-4648-bd76-ea5461a114f8/wutisikomolozabaw.pdf
- https://uploads.strikinglycdn.com/files/6ba2fa94-00a7-40d7-ab20-87f53a4a7104/zugojojadikadujuwuxemosu.pdf
- https://uploads.strikinglycdn.com/files/c3446945-4c09-48e3-b8c8-f144940bc3d6/rimodugo.pdf
- https://uploads.strikinglycdn.com/files/3b30d35e-03be-41a5-b949-0213fd550e14/92194914869.pdf
- https://site-1037274.mozfiles.com/files/1037274/ziruf.pdf
- https://site-1036852.mozfiles.com/files/1036852/27735985878.pdf
- https://site-1036816.mozfiles.com/files/1036816/fomunoroxizoweg.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1037274.mozfiles.com
- site-1036852.mozfiles.com
- site-1036816.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report