SUSPICIOUS — teveguzapo_jifabotusid_mepavogikes.pdf
SUSPICIOUS — teveguzapo_jifabotusid_mepavogikes.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e6a7cd2102e234f89f2212b7e0f3cc79fef0bd15d9c18a5bab80446108918127 - SHA-1:
84ea9412543ee4d0f69d1f8b7807a6aa07b327de - MD5:
6551ee207bf8b6d3339884d7246c40da - ssdeep:
1536:VwGFjrz9ra8elb3wtrfpTvr3UPaRM/FMrU5GmvR:V9Fjf4jcfpTT3UPaEFMXu - TLSH:
T17836CFF34097DC4CBBCA5B07BDE611AA4548EA89A237D3A0089C3B2DD4BC6ED7E40551 - Submitted as: teveguzapo_jifabotusid_mepavogikes.pdf
- File type: pdf · Size: 65352 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=super%20takumar%20lens%20manual, https://uploads.strikinglycdn.com/files/5298a01b-62f0-476b-9159-df8ae08b01f4/hamilton_beach_flexbrew_manual.pdf, https://uploads.strikinglycdn.com/files/4195b486-b95e-48b5-8b62-2cd972d40738/hunter_x_hunter_dubbed_torrent.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=super%20takumar%20lens%20manual
- https://uploads.strikinglycdn.com/files/5298a01b-62f0-476b-9159-df8ae08b01f4/hamilton_beach_flexbrew_manual.pdf
- https://uploads.strikinglycdn.com/files/4195b486-b95e-48b5-8b62-2cd972d40738/hunter_x_hunter_dubbed_torrent.pdf
- https://uploads.strikinglycdn.com/files/651c2fe9-28ce-49fe-8a59-cd9ae2bc2307/45841348908.pdf
- https://uploads.strikinglycdn.com/files/676a2a14-06d6-4ab3-9695-0f9e40745909/bovinonezezut.pdf
- https://uploads.strikinglycdn.com/files/0593e7a8-a5cb-4b96-bb64-d1c004816b1f/fesejenabewatig.pdf
- https://uploads.strikinglycdn.com/files/905c58a6-cc66-45fe-8f4d-31ef7ca2c87d/lidukigexajemaguramat.pdf
- https://uploads.strikinglycdn.com/files/f67ba3a4-b6a6-4a1c-8eb8-df20ccaaadfa/c43_amg_bhp.pdf
- https://uploads.strikinglycdn.com/files/8ef60f8b-dce7-4c39-891a-52dc0077fa0b/xutubejumokalunin.pdf
- https://s3.amazonaws.com/mejifavo/17368154353.pdf
- https://s3.amazonaws.com/jeduzizonox/vobanesavexi.pdf
- https://s3.amazonaws.com/bededuxotulapil/kifupogelagedulubuf.pdf
- https://s3.amazonaws.com/gidibesuxi/91424216684.pdf
- https://uploads.strikinglycdn.com/files/bf093c7b-9d36-4bd8-bdd0-29c4f799b5e0/monster_manual_5e_download.pdf
- https://uploads.strikinglycdn.com/files/d096386a-769f-485a-ba95-fab3d6032905/47501052026.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/bujuvilifagajezo.pdf
- https://cdn.shopify.com/s/files/1/0481/6250/4855/files/android_emulator_pc_nox_player.pdf
- https://cdn-cms.f-static.net/uploads/4366653/normal_5f873c1dcb840.pdf
- https://cdn-cms.f-static.net/uploads/4368782/normal_5f8f8dc09156c.pdf
- https://cdn-cms.f-static.net/uploads/4371248/normal_5f8e64ebc2f0a.pdf
- https://cdn-cms.f-static.net/uploads/4377931/normal_5f925266850c7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report