SUSPICIOUS — 280961.pdf
SUSPICIOUS — 280961.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b5f9c35de689393291859877aaaf65d97118cdd869d685ac8f4d6558c02a9517 - SHA-1:
a9ca9bc3273cd9893a10e8c3de959c3991839de8 - MD5:
a7cc1a674d2dae52563b11725ca42f6b - ssdeep:
768:JgGzpDhpDEX8o7zNrFxj6xsDaulEXKvW6xvUc0D28GTh:qGFtpSdj6CDaulEXKeEx06lh - TLSH:
T1A6307DF350A7EC4C7A97AB13BDA6115A6489C34C623697A054CC7B3CC4BC6BC7E40961 - Submitted as: 280961.pdf
- File type: pdf · Size: 38919 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=jual%20boneka%20chong%20pororo%20video, https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/foxisewowixubetaja.pdf, https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/2137176.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=jual%20boneka%20chong%20pororo%20video
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/foxisewowixubetaja.pdf
- https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/2137176.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rugatu-rugot.pdf
- https://zugufavowi.weebly.com/uploads/1/3/0/8/130874222/538bf98.pdf
- https://juzugimigiroteg.weebly.com/uploads/1/3/2/3/132302883/mivevoluni.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nipomomuka_gisotufeje.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/10610.pdf
- https://uploads.strikinglycdn.com/files/2bb7b8f8-62d2-4ae3-a1ea-ad5d9eac8868/83791448538.pdf
- https://uploads.strikinglycdn.com/files/61b47604-7d95-47d6-9254-c50936acaf57/24488074740.pdf
- https://zugufavowi.weebly.com/uploads/1/3/0/8/130874222/f3ae0daca226dc.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/sixukejomiwewanage.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/4973474.pdf
- https://cdn-cms.f-static.net/uploads/4375350/normal_5f8b62049dba1.pdf
- https://cdn-cms.f-static.net/uploads/4366645/normal_5f87408680185.pdf
- https://cdn-cms.f-static.net/uploads/4367301/normal_5f8a13814e298.pdf
- https://cdn-cms.f-static.net/uploads/4369327/normal_5f8a0af75eae6.pdf
- https://cdn.shopify.com/s/files/1/0502/9462/0333/files/android_handler_postdelayed_ui_thread.pdf
- https://cdn.shopify.com/s/files/1/0266/9723/6650/files/bejezesuxuzawesafuzijupu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- mupibidegupek.weebly.com
- fewevivib.weebly.com
- vuxozajuje.weebly.com
- zugufavowi.weebly.com
- juzugimigiroteg.weebly.com
- jakedekokobara.weebly.com
- uploads.strikinglycdn.com
- mogilifus.weebly.com
- lodirunesu.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- v.no
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report