SUSPICIOUS — jajemezabe.pdf
SUSPICIOUS — jajemezabe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0780348d2fabe47f0e6e03aedb680c613e2cedec2f8e279a545c0ac8f66bc236 - SHA-1:
1a231ab0266645997b2200c83093071a7a22efb4 - MD5:
6a50d2bcde9af66d9983a16284d06dc5 - ssdeep:
768:6gGzpDEHHrkPthP0phdpP3/DRZ4Y27AwhIHMnNTAYMRm:nGFAHLl/3P3/9OHlaHqTAYMRm - TLSH:
T12C319EF76097FD8C3A8ABF079EAA0119619AD7886033D7605898366DC4BC7FD6F40520 - Submitted as: jajemezabe.pdf
- File type: pdf · Size: 41993 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=far+cry+2+diamond+map, https://uploads.strikinglycdn.com/files/20f5485d-3466-44db-bfd7-e39a6f378bf0/26031978456.pdf, https://uploads.strikinglycdn.com/files/ade6e9b1-446f-408f-ac50-43b299cfee6e/80430814315.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=far+cry+2+diamond+map
- https://uploads.strikinglycdn.com/files/20f5485d-3466-44db-bfd7-e39a6f378bf0/26031978456.pdf
- https://uploads.strikinglycdn.com/files/ade6e9b1-446f-408f-ac50-43b299cfee6e/80430814315.pdf
- https://uploads.strikinglycdn.com/files/6e35f49c-b6df-4a97-b1de-b993af282432/zarigitiwawefulupovigubi.pdf
- https://uploads.strikinglycdn.com/files/89218e64-f817-4ecf-9c9b-baf539713258/vevexomupamosipun.pdf
- https://uploads.strikinglycdn.com/files/e62d9719-18ec-46af-8665-f99fc671a1a0/3644403142.pdf
- http://fojepaj.fighr.org/uploads/1/3/1/6/131607600/lukefigepid-fexorobuwemile-liwavuzemu.pdf
- https://site-1036980.mozfiles.com/files/1036980/gebejos.pdf
- https://site-1037130.mozfiles.com/files/1037130/77926162221.pdf
- https://site-1037222.mozfiles.com/files/1037222/47685245664.pdf
- https://site-1039809.mozfiles.com/files/1039809/vutakojarapugulewuxi.pdf
- https://uploads.strikinglycdn.com/files/55e04006-2e56-4618-992d-7c7ef9109b13/loworuzodijazisalo.pdf
- https://uploads.strikinglycdn.com/files/db05ad28-897d-4865-8985-ea49fa9839ad/56775495991.pdf
- https://uploads.strikinglycdn.com/files/8ff6e564-7de1-423a-baa7-5ffe8f00f543/pazoneponibumowabera.pdf
- https://uploads.strikinglycdn.com/files/790b1916-ed10-4918-b5bf-83a69601cff8/tukiwekix.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- fojepaj.fighr.org
- site-1036980.mozfiles.com
- site-1037130.mozfiles.com
- site-1037222.mozfiles.com
- site-1039809.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report