SUSPICIOUS — bojegaziva.pdf
SUSPICIOUS — bojegaziva.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
ee825cabcd561c3631fa5b32afd3853d6e51b32e83aacd6c137eb6dbd5912dff - SHA-1:
20528ca5a1c94ca30cedfffccb563703d942516d - MD5:
935230774efe1912fee058f349d43a65 - ssdeep:
768:9gGzpDPwS/n6BnPKoPebxHLoYNMi0kD/FAWlaDbBLlkaFg4TRBovnSRMZtBfCoRq:+GFjdZBAHLkaDRBovnuGgwueIKNE - TLSH:
T11A339DF35093ED8C7A87EF837DDA269A9109C28C6132A765409C366CC47C2BE3F40A51 - Submitted as: bojegaziva.pdf
- File type: pdf · Size: 49190 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=antoine+de+saint-+exup%25C3%25A9ry+wind+sand+and+stars+pdf, https://cdn.shopify.com/s/files/1/0432/1512/6692/files/let_it_snow_john_green.pdf, https://cdn.shopify.com/s/files/1/0484/3510/1850/files/rerosedibosepevakiresura.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=antoine+de+saint-+exup%25C3%25A9ry+wind+sand+and+stars+pdf
- https://cdn.shopify.com/s/files/1/0432/1512/6692/files/let_it_snow_john_green.pdf
- https://cdn.shopify.com/s/files/1/0484/3510/1850/files/rerosedibosepevakiresura.pdf
- https://cdn.shopify.com/s/files/1/0485/2505/0018/files/colts_neck_schools_transportation.pdf
- https://cdn.shopify.com/s/files/1/0438/9866/7163/files/aid_another_pathfinder_spell.pdf
- https://cdn.shopify.com/s/files/1/0440/5824/7320/files/rodojatowineranuzufar.pdf
- https://uploads.strikinglycdn.com/files/c16a2ffd-fd99-41d8-92be-cfa9bc9e5e11/gabelepoxabumijolur.pdf
- https://uploads.strikinglycdn.com/files/4eb65e2b-3c54-4c65-bb2c-e88fc6206bfb/819677391.pdf
- https://uploads.strikinglycdn.com/files/8f54ef5a-650c-4f8d-99ac-0b88b6358bb1/56213840968.pdf
- https://uploads.strikinglycdn.com/files/c42a02fe-e8b9-473d-bec2-97acb694afe2/zabividobosab.pdf
- https://uploads.strikinglycdn.com/files/8001a341-65c9-4fe7-8b58-5cb5256a3c02/wibaroterulepuvadus.pdf
- https://uploads.strikinglycdn.com/files/883d8df9-2b9e-4c2f-9cf3-fd0fd9786965/nafida.pdf
- https://uploads.strikinglycdn.com/files/9f45a1b5-36c6-4777-bd04-baf17fe7b463/vazopatasu.pdf
- https://uploads.strikinglycdn.com/files/fbce9c78-318c-4076-9bf8-b21131f85861/37806886947.pdf
- https://uploads.strikinglycdn.com/files/53cd674a-5f24-43b9-aa0e-dad964292e1e/kogumikis.pdf
- https://cdn.shopify.com/s/files/1/0477/5179/0748/files/wilutabiv.pdf
- https://cdn.shopify.com/s/files/1/0436/3812/8793/files/cody_parkey_tennessee_contract.pdf
- https://cdn.shopify.com/s/files/1/0483/6612/5207/files/chuunibyou_demo_koi_ga_shitai_ren_lite.pdf
- https://cdn.shopify.com/s/files/1/0485/1577/6667/files/the_declaratory_act_cause_and_effect.pdf
- https://cdn.shopify.com/s/files/1/0483/8732/6110/files/8647514064.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report