SUSPICIOUS — gajiwegojinobamo.pdf
SUSPICIOUS — gajiwegojinobamo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ac9df6ef769e375643b37a0feda6bc091168a79ab6b317afcd860814cb530999 - SHA-1:
f5e6a6fcfb92c6185b514a590f8dcf5d5169b2f9 - MD5:
c66e44cf93a1c47fce59892225401a45 - ssdeep:
1536:nGFW6kqByDGPL2dhc3BXQYHDGxqgtlwWq7+sXCumIMUrYvIx5jLWCV8bJ68:GFW6k8kGz8S9GZDwwZWYvIx5jr8bT - TLSH:
T1F73AE1F31057CC8CAA86EB03BDF512AC2049CB896137675405CDBA6CC5BC6BC6EA0D61 - Submitted as: gajiwegojinobamo.pdf
- File type: pdf · Size: 96153 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=gradle%20tutorials%20point%20pdf, https://cdn-cms.f-static.net/uploads/4386591/normal_5f982e189c23b.pdf, https://cdn.shopify.com/s/files/1/0462/3876/1109/files/zunodiwopufusuxome.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=gradle%20tutorials%20point%20pdf
- https://cdn-cms.f-static.net/uploads/4386591/normal_5f982e189c23b.pdf
- https://cdn.shopify.com/s/files/1/0462/3876/1109/files/zunodiwopufusuxome.pdf
- https://cdn.shopify.com/s/files/1/0485/0607/7339/files/french_cleat_hanger_walmart.pdf
- https://s3.amazonaws.com/jebokizez/cessna_152_weight_and_balance.pdf
- https://uploads.strikinglycdn.com/files/7f252242-16f2-4ca0-82b4-750e21c6bfcc/likiminefixerawuguz.pdf
- https://uploads.strikinglycdn.com/files/d990402a-c7f9-4dce-b5ac-63707a9cda96/rofasadugawepizokobejelow.pdf
- https://uploads.strikinglycdn.com/files/ab34d37a-9e23-49e9-bc87-2238c39b2914/23696648682.pdf
- https://s3.amazonaws.com/jipowumat/fudosiwasawif.pdf
- https://s3.amazonaws.com/dalava/91397164581.pdf
- https://s3.amazonaws.com/daraniwekamidir/cade_simu_manual.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f943dd3d064d.pdf
- https://s3.amazonaws.com/tadovu/william_wordsworth_biography.pdf
- https://manuxemewawi.weebly.com/uploads/1/3/4/4/134443751/9987804.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- manuxemewawi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report