SUSPICIOUS — minumobedafaxil.pdf
SUSPICIOUS — minumobedafaxil.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c73c7d5b0d849f0e0f2dbcef87167200d26badc1daa45cccf7c3967c5fee6f16 - SHA-1:
d157146494a5f173bafc6a30d4764361ead1e628 - MD5:
c24ff0003abc5b76d883f9b4e95bb97c - ssdeep:
768:rgGzpDdpZ0y6b34qKPZ1eAfLZsCiyoskvPv5Jq1Uu6212B/esOBvEcsosM:UGFRpZoZCiXskvHXqU2qTcsosM - TLSH:
T104338DF31097ED4C3E8BAB53ADAB11A96489D74C6137A7A04488772CC0BC9BE7F01911 - Submitted as: minumobedafaxil.pdf
- File type: pdf · Size: 47709 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=caricature%20plantu%20attentats%20du%2011%20septembre, https://site-1037124.mozfiles.com/files/1037124/85516627043.pdf, https://site-1048552.mozfiles.com/files/1048552/40058125604.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=caricature%20plantu%20attentats%20du%2011%20septembre
- https://site-1037124.mozfiles.com/files/1037124/85516627043.pdf
- https://site-1048552.mozfiles.com/files/1048552/40058125604.pdf
- https://site-1043880.mozfiles.com/files/1043880/fallout_shelter_apk_latest_version.pdf
- https://site-1043686.mozfiles.com/files/1043686/43526743306.pdf
- https://cdn.shopify.com/s/files/1/0435/2878/1988/files/31504154703.pdf
- https://cdn.shopify.com/s/files/1/0497/9287/6705/files/cavern_of_souls_edz_bounty.pdf
- https://cdn.shopify.com/s/files/1/0268/7837/8157/files/45038169120.pdf
- https://cdn.shopify.com/s/files/1/0432/5759/4011/files/52355662892.pdf
- https://cdn.shopify.com/s/files/1/0437/4278/9786/files/seronajolozanevonu.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/foburadip.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/viwibutesu.pdf
- https://fevixivosetakub.weebly.com/uploads/1/3/2/6/132681861/pukigupa.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/9400458.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f86fea4421ac.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f8880d646451.pdf
- https://cdn-cms.f-static.net/uploads/4366959/normal_5f872fad4443e.pdf
- https://cdn-cms.f-static.net/uploads/4368953/normal_5f87e25c63566.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f87653d57412.pdf
- https://uploads.strikinglycdn.com/files/9e7ad969-2ecd-49e5-982e-af7be89206f3/selevuxudulisex.pdf
- https://uploads.strikinglycdn.com/files/684703e2-4f82-44a3-9c2b-980575d2ab0b/97423856841.pdf
- https://uploads.strikinglycdn.com/files/f40047e3-b8ee-4254-a4e4-37893be6017c/25721346345.pdf
- https://uploads.strikinglycdn.com/files/5ed82645-7f24-4a2f-b5ed-31941eca5d28/89601419959.pdf
- https://cdn.shopify.com/s/files/1/0438/6209/8085/files/vanillylmandelic_acid_test_instructions.pdf
- https://cdn.shopify.com/s/files/1/0465/0077/4046/files/bloons_tower_defense_unblocked_3.pdf
Embedded domains
- ggtraff.ru
- site-1037124.mozfiles.com
- site-1048552.mozfiles.com
- site-1043880.mozfiles.com
- site-1043686.mozfiles.com
- cdn.shopify.com
- xojerajap.weebly.com
- medizagokitoni.weebly.com
- fevixivosetakub.weebly.com
- riwisasivituw.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report