SUSPICIOUS — siduru-wojexej-filuko.pdf
SUSPICIOUS — siduru-wojexej-filuko.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c9625ff8e6e51f788566973fb98251999db16b8e709bdd0ffbdfffae4a4e879a - SHA-1:
d1a4bf3a4479e7d4b83a688907e9edfb51acb2e8 - MD5:
89e866918060e80c02e111ec1317f0e1 - ssdeep:
768:wgGzpDqpMzVqpnaA5RRPFrrHhOh/PctTbfXe9w3L99Nu4rJD:dGF+pMz+x9rVAAzXe9ubrJD - TLSH:
T1B433AFF39077ED4CBA8EAF07ADBA0154604AC78C612397A054C8671DC1BC6FE2F00A25 - Submitted as: siduru-wojexej-filuko.pdf
- File type: pdf · Size: 50267 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=the%20workbench%20design%20book%20pdf, https://site-1037275.mozfiles.com/files/1037275/momebudapu.pdf, https://site-1040424.mozfiles.com/files/1040424/sosuno.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=the%20workbench%20design%20book%20pdf
- https://site-1037275.mozfiles.com/files/1037275/momebudapu.pdf
- https://site-1040424.mozfiles.com/files/1040424/sosuno.pdf
- https://site-1036684.mozfiles.com/files/1036684/97272010187.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f87154093c09.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f86f6f8c48d6.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f870133a973d.pdf
- https://uploads.strikinglycdn.com/files/2d9d8241-291a-4cb2-a144-733743bc51fd/84459428451.pdf
- https://uploads.strikinglycdn.com/files/6252a8e9-22ec-46ce-9134-03e7fce2dc7d/kazok.pdf
- https://uploads.strikinglycdn.com/files/1427f53b-9c87-4617-9b37-496acad13818/libife.pdf
- https://uploads.strikinglycdn.com/files/82e4739a-7b11-4d11-8ea6-325c2b38ee79/37460961563.pdf
- https://uploads.strikinglycdn.com/files/f6cc4f12-96ad-4241-b1bf-3a44959a8795/rawalunere.pdf
- https://uploads.strikinglycdn.com/files/3fe03617-b01b-4d25-9986-59de91202bd9/jukumaxaxuvivavisawun.pdf
- https://uploads.strikinglycdn.com/files/b2af440e-bb49-4374-8477-9575b6d7f830/33641675274.pdf
- https://site-1038725.mozfiles.com/files/1038725/nuzed.pdf
- https://site-1040178.mozfiles.com/files/1040178/58593751562.pdf
- https://site-1040347.mozfiles.com/files/1040347/46807282587.pdf
- https://site-1038949.mozfiles.com/files/1038949/33556101305.pdf
- https://site-1039510.mozfiles.com/files/1039510/89056032605.pdf
- https://uploads.strikinglycdn.com/files/826bbec7-8c4b-4230-b73f-3f3bb93406e3/jufejigedoxarupexukejof.pdf
- https://uploads.strikinglycdn.com/files/d42964d8-512e-47c7-88fb-8dafe8b01ee6/wonexepe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- site-1037275.mozfiles.com
- site-1040424.mozfiles.com
- site-1036684.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038725.mozfiles.com
- site-1040178.mozfiles.com
- site-1040347.mozfiles.com
- site-1038949.mozfiles.com
- site-1039510.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report