SUSPICIOUS — podewowasil.pdf
SUSPICIOUS — podewowasil.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
cb4549e55a7c1893e842618b1c311e738d0eb78e1c469dc84132b696ff801750 - SHA-1:
fecfa1985df8bb86ab1d7c90885f98c2bca9a404 - MD5:
cce690520725e0d2c6850f2a577bc069 - ssdeep:
768:pgGzpDLpCeoQ34TNTtlxg4iD6c7+Z1/z91b/FPwhw4nCQ+C4H:KGFHpala4iu4I1/B1b/Fb4F+C4H - TLSH:
T1AD329EF34097ED4CBA87AB079EEA10595089C34D2237E7B484886B2DD4BC5BDBF50960 - Submitted as: podewowasil.pdf
- File type: pdf · Size: 47442 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=i%20language%20vs%20you%20language, https://uploads.strikinglycdn.com/files/6ba6d0a1-1f53-4ae5-b8ed-80e5069e6b5a/dewavunabibajon.pdf, https://uploads.strikinglycdn.com/files/048c9a5f-2143-49fb-8740-8c9d775c3442/xanokusowowevuvef.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=i%20language%20vs%20you%20language
- https://uploads.strikinglycdn.com/files/6ba6d0a1-1f53-4ae5-b8ed-80e5069e6b5a/dewavunabibajon.pdf
- https://uploads.strikinglycdn.com/files/048c9a5f-2143-49fb-8740-8c9d775c3442/xanokusowowevuvef.pdf
- https://uploads.strikinglycdn.com/files/3da71142-0122-4c60-975e-70ee6281e6f5/kowikipuzu.pdf
- https://uploads.strikinglycdn.com/files/1f6f3819-596c-47e4-a507-63cf1622c62f/84877752434.pdf
- https://cdn.shopify.com/s/files/1/0496/7560/0036/files/ucsd_nursing_transfer_requirements.pdf
- https://cdn.shopify.com/s/files/1/0432/7456/7843/files/bijofesalurulediveged.pdf
- https://site-1040132.mozfiles.com/files/1040132/11147867005.pdf
- https://site-1037241.mozfiles.com/files/1037241/nakesuxofexilewoxu.pdf
- https://site-1037840.mozfiles.com/files/1037840/fuvelopijopasoked.pdf
- https://site-1041688.mozfiles.com/files/1041688/latilojo.pdf
- https://site-1043203.mozfiles.com/files/1043203/84203464813.pdf
- https://site-1039646.mozfiles.com/files/1039646/ropog.pdf
- https://site-1042556.mozfiles.com/files/1042556/80125591262.pdf
- https://site-1039668.mozfiles.com/files/1039668/zezezawogegonagaj.pdf
- https://uploads.strikinglycdn.com/files/62487786-e0d8-48e0-8b37-8a4f1752516b/kudokawidasagojatirudipam.pdf
- https://uploads.strikinglycdn.com/files/a8eeda5e-f80c-4f30-83bc-a292ff447a7e/34671651605.pdf
- https://uploads.strikinglycdn.com/files/1424d360-7d0a-4d63-8ec2-e0024f8cf8c1/patow.pdf
- https://uploads.strikinglycdn.com/files/aa1ad417-897b-409f-826b-5b0f3cd5796a/72595587187.pdf
- https://uploads.strikinglycdn.com/files/eb20396e-4da5-47b6-9f8a-7576c6f004c7/mitetavelewupufipadug.pdf
- https://uploads.strikinglycdn.com/files/f8f8c374-acce-4b8c-91a7-dc95d2db5333/1279491815.pdf
- https://uploads.strikinglycdn.com/files/ae87783a-daa2-44d7-8db6-a7eec64a5ec5/73032067526.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1040132.mozfiles.com
- site-1037241.mozfiles.com
- site-1037840.mozfiles.com
- site-1041688.mozfiles.com
- site-1043203.mozfiles.com
- site-1039646.mozfiles.com
- site-1042556.mozfiles.com
- site-1039668.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report