SUSPICIOUS — gapiwojara.pdf
SUSPICIOUS — gapiwojara.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
cb04675b530d0e0d3586b8c0bb7ae3d57e1946a7e4d12c87daa94ebba6b44cb1 - SHA-1:
f1c2c66de3781bfbab3adeae9d8f1f49a5154904 - MD5:
d51d05d28287205876f6942a80e501ce - ssdeep:
768:JgGzpDZp9C84GTGGacZMkdAm+Ib99RgOMNIhwRbImHZ8dFNRi7XsCp6KezSAE3SU:qGFFp97+MMJRsmZ81Ri7czKFAE3SrGNt - TLSH:
T12B339DF39093ED4CBA8FEB136DEB11AB6189D688613397601448372DD4BC6BD7D50820 - Submitted as: gapiwojara.pdf
- File type: pdf · Size: 48778 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pokemon%20go%20pvp%20rewards, https://site-1038985.mozfiles.com/files/1038985/desugukejigogoxojuma.pdf, https://site-1040613.mozfiles.com/files/1040613/nibubi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pokemon%20go%20pvp%20rewards
- https://site-1038985.mozfiles.com/files/1038985/desugukejigogoxojuma.pdf
- https://site-1040613.mozfiles.com/files/1040613/nibubi.pdf
- https://site-1048522.mozfiles.com/files/1048522/47811449494.pdf
- https://site-1042360.mozfiles.com/files/1042360/90892545779.pdf
- https://site-1039779.mozfiles.com/files/1039779/mitazevip.pdf
- https://cdn.shopify.com/s/files/1/0482/2899/1130/files/walevitisudab.pdf
- https://cdn.shopify.com/s/files/1/0266/7613/4082/files/47799784363.pdf
- https://cdn.shopify.com/s/files/1/0493/9651/4972/files/46051856971.pdf
- https://cdn.shopify.com/s/files/1/0483/8693/2894/files/14968064426.pdf
- https://cdn.shopify.com/s/files/1/0499/1084/1512/files/57252404795.pdf
- https://cdn.shopify.com/s/files/1/0478/3567/6831/files/jojiwikaz.pdf
- https://cdn.shopify.com/s/files/1/0484/8972/6107/files/65282198202.pdf
- https://cdn.shopify.com/s/files/1/0431/0158/5562/files/28873166174.pdf
- https://cdn.shopify.com/s/files/1/0495/9764/4964/files/nabuzubokanojin.pdf
- https://cdn.shopify.com/s/files/1/0478/8276/4454/files/easter_bunny_clipart_vector.pdf
- https://cdn.shopify.com/s/files/1/0481/3340/6871/files/food_chain_vocabulary_worksheet_answers.pdf
- https://uploads.strikinglycdn.com/files/0e149f9b-936a-4a54-acd5-a388e4c73f76/20100267865.pdf
- https://uploads.strikinglycdn.com/files/6144bedd-c96e-4f80-8133-1aebded7e0d7/voginuve.pdf
- https://uploads.strikinglycdn.com/files/e603362b-0dfa-422a-a7c4-af8a95e8ec43/lofinijovefebegujezelol.pdf
- https://uploads.strikinglycdn.com/files/7e579054-224a-48f5-9288-1f1c563f9139/laduzajutetab.pdf
- https://uploads.strikinglycdn.com/files/c2d05661-aaad-4167-9cc4-ee275ad32db7/tedufebogoxozesiwixupa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- site-1038985.mozfiles.com
- site-1040613.mozfiles.com
- site-1048522.mozfiles.com
- site-1042360.mozfiles.com
- site-1039779.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report