SUSPICIOUS — bexanara_ludewo.pdf
SUSPICIOUS — bexanara_ludewo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
b47597a32a180141e6576b84b88cee08188c67f3c9a1c5ae6e49fd9e30a126bf - SHA-1:
773e343cfcf241de7c9ae1149e53ea6d65583ea0 - MD5:
b6a49a0b6ceca33f2b6585a31da3a189 - ssdeep:
768:ygGzpDWpdBcCAo7OietPJpThg0DsVMEBS21jz4Bg+qZDOoX1bY/lvN5njo:vGFaptV+qZDOAbA5njo - TLSH:
T191316DF32497ED8D3ACBDB936CA71666258AC78C6232E791048C772CD5AC5BD6F00814 - Submitted as: bexanara_ludewo.pdf
- File type: pdf · Size: 40029 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=chanson%20j, https://cdn.shopify.com/s/files/1/0483/7582/4544/files/spider_spikes_or_quik_trak.pdf, https://cdn.shopify.com/s/files/1/0501/8697/7441/files/virilinebudo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=chanson%20j
- https://cdn.shopify.com/s/files/1/0483/7582/4544/files/spider_spikes_or_quik_trak.pdf
- https://cdn.shopify.com/s/files/1/0501/8697/7441/files/virilinebudo.pdf
- https://cdn.shopify.com/s/files/1/0486/1706/2558/files/rarexogipusanajopuda.pdf
- https://cdn.shopify.com/s/files/1/0438/6629/2389/files/kosusepatutivudelaromo.pdf
- https://cdn.shopify.com/s/files/1/0492/3136/4252/files/guninemugavajawoxelalagep.pdf
- https://cdn.shopify.com/s/files/1/0430/6377/1293/files/34335403971.pdf
- https://cdn.shopify.com/s/files/1/0481/7829/9031/files/pearson_anatomy_and_physiology_textbook.pdf
- https://cdn.shopify.com/s/files/1/0493/1108/8799/files/77780197229.pdf
- https://cdn.shopify.com/s/files/1/0496/3038/0181/files/wogabagujugigefag.pdf
- https://cdn.shopify.com/s/files/1/0498/1007/9898/files/northwestern_california_university_school_of_law_reviews.pdf
- https://cdn-cms.f-static.net/uploads/4374954/normal_5f8a3ead10775.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f87f2c2b87d2.pdf
- https://cdn-cms.f-static.net/uploads/4373757/normal_5f89993b5c356.pdf
- https://cdn-cms.f-static.net/uploads/4367960/normal_5f8a3c5a6305d.pdf
- https://cdn.shopify.com/s/files/1/0482/5920/3234/files/ruzixezijawalod.pdf
- https://cdn.shopify.com/s/files/1/0482/2014/3773/files/disney_buying_captain_marvel_tickets.pdf
- https://cdn.shopify.com/s/files/1/0484/8467/9842/files/78187352521.pdf
- https://cdn.shopify.com/s/files/1/0498/7659/8942/files/traeger_beef_brisket_burnt_ends.pdf
- https://cdn.shopify.com/s/files/1/0431/7347/8560/files/85745420198.pdf
- https://uploads.strikinglycdn.com/files/1eb61402-0203-4ecb-b8a3-d4223dea96d2/mekewetoxiwadilukanadu.pdf
- https://uploads.strikinglycdn.com/files/a766566a-e0a9-4875-ac31-a4f8726d885b/76511197545.pdf
- https://uploads.strikinglycdn.com/files/d7294c19-1312-4bc6-a687-488b8704ccac/gepemuxagiwomawo.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87fbfa24ead.pdf
- https://cdn-cms.f-static.net/uploads/4378628/normal_5f8ba1a94d660.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report