SUSPICIOUS — gudij.pdf
SUSPICIOUS — gudij.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
af07a8a14ee067f62b861a0825efde5c693c92866c84d5a935eef8b45563a0c8 - SHA-1:
1689a85ab9b8ed0771dee6fe1de845032a5da412 - MD5:
8ba643fd9c28049b70d9dc2e444fe8fe - ssdeep:
768:0gGzpDfFWpJuUMMTqygHEXwVX8qzHBEsMo6xuwMtMAs:BGFTFaqyKeKRzHBEco4s - TLSH:
T19D31AEF3A097ED8C7E876F836EBB1558504A824E7122576024E87B7DC4B86FD2F10861 - Submitted as: gudij.pdf
- File type: pdf · Size: 42755 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=ingles%20para%20viagens%20pdf, https://uploads.strikinglycdn.com/files/7d7bec0f-e4b2-4cc1-9df1-c8ed22a8141b/56533752190.pdf, https://cdn.shopify.com/s/files/1/0499/8289/8326/files/35801740400.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=ingles%20para%20viagens%20pdf
- https://uploads.strikinglycdn.com/files/7d7bec0f-e4b2-4cc1-9df1-c8ed22a8141b/56533752190.pdf
- https://cdn.shopify.com/s/files/1/0499/8289/8326/files/35801740400.pdf
- https://s3.amazonaws.com/nigimul/6980308863.pdf
- https://uploads.strikinglycdn.com/files/f26c0110-bf29-4eab-b59f-d14b3a300b84/pepofasusapevisir.pdf
- https://nimukitu.weebly.com/uploads/1/3/4/2/134266418/rasefeku.pdf
- https://s3.amazonaws.com/jofunozuzof/91699443180.pdf
- https://uploads.strikinglycdn.com/files/1d5f8966-4891-4185-8bc8-9578e8dfa2de/48993086779.pdf
- https://uploads.strikinglycdn.com/files/5ea09128-85ca-430a-934a-ca8d431c724c/book_of_shadows_free.pdf
- https://cdn.shopify.com/s/files/1/0503/7834/2598/files/interstellar_google_drive_english.pdf
- https://s3.amazonaws.com/vezumobigodub/76474161090.pdf
- https://uploads.strikinglycdn.com/files/933a482c-858d-4e84-a4ac-368ed11fe795/green_lantern_new_52.pdf
- https://uploads.strikinglycdn.com/files/3ff8c304-1691-4673-9471-59f757455a7e/27017942627.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- nimukitu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report