SUSPICIOUS — masamixofu_monebunajidan.pdf
SUSPICIOUS — masamixofu_monebunajidan.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
dcb655572c5c8aa524c10f11ed40201ef51938cf7e057b552c443df069c554ba - SHA-1:
b0de6e74cf8cdcaa77f4c9564e4c2011e7ee4b03 - MD5:
ac38966a29c646cc127f77cb83e921d8 - ssdeep:
768:JgGzpDApCFuKkjdl7kW+WN07LtpdvBjd3P0jBAlMbAfvgX1VsMn5SniBsKcUZfd:qGF8p1etX5d38jbbAfK1vvOKcUZfd - TLSH:
T128328DF35097ED4CBA8BAB03EDAA145A54CED78C6137E790158C276CC4BC6AD7E10860 - Submitted as: masamixofu_monebunajidan.pdf
- File type: pdf · Size: 44282 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=pc%20cleanup%20free, https://cdn-cms.f-static.net/uploads/4366628/normal_5f87593fbb99d.pdf, https://cdn-cms.f-static.net/uploads/4371023/normal_5f88a076c529e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=pc%20cleanup%20free
- https://cdn-cms.f-static.net/uploads/4366628/normal_5f87593fbb99d.pdf
- https://cdn-cms.f-static.net/uploads/4371023/normal_5f88a076c529e.pdf
- https://cdn-cms.f-static.net/uploads/4369797/normal_5f895fea789c8.pdf
- https://uploads.strikinglycdn.com/files/1dba98ed-2f57-4a23-bb4c-ecbf37d7359d/jomejisenozita.pdf
- https://uploads.strikinglycdn.com/files/4b9356d5-aa78-4dd6-abec-88b7f530288e/56974569619.pdf
- https://uploads.strikinglycdn.com/files/84196d3c-88b4-475d-86d5-2b4fc9e5a9fe/fofifof.pdf
- https://uploads.strikinglycdn.com/files/2380b616-2636-40a6-a7ea-1a5cbae59db4/gokopekezixoxagudil.pdf
- https://uploads.strikinglycdn.com/files/fcd63400-0d0f-4471-9fa1-74fce0fabfa1/70362919204.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f8830505ad06.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f87194180c82.pdf
- https://cdn-cms.f-static.net/uploads/4369514/normal_5f89b098173bb.pdf
- https://cdn-cms.f-static.net/uploads/4367313/normal_5f88161da4371.pdf
- https://cdn-cms.f-static.net/uploads/4366312/normal_5f87109de89d4.pdf
- https://uploads.strikinglycdn.com/files/3a711897-839b-4ffd-ad04-a6f485da186e/19178026702.pdf
- https://uploads.strikinglycdn.com/files/e2ca4e8f-75d0-4cc7-9bfa-9f98154c8135/duwaf.pdf
- https://cdn.shopify.com/s/files/1/0496/5856/0661/files/grove_city_parks_and_recreation.pdf
- https://cdn.shopify.com/s/files/1/0266/8586/6177/files/minecraft_realms_lag_reddit.pdf
- https://cdn.shopify.com/s/files/1/0496/0023/3636/files/3103586897.pdf
- https://vuxilimibipemop.weebly.com/uploads/1/3/1/4/131453056/kovozo_gekinolexar_wipuxuturox.pdf
- https://gikanirirexenad.weebly.com/uploads/1/3/0/7/130776133/08d3cbded.pdf
- https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/169792.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/poralujoneno.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- vuxilimibipemop.weebly.com
- gikanirirexenad.weebly.com
- lodirunesu.weebly.com
- dejolezeg.weebly.com
- jatorogerujew.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report