SUSPICIOUS — wejafutoreninebozo.pdf
SUSPICIOUS — wejafutoreninebozo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
0ca25970392197062d15779589226905eff5f5e0aa4229e4ca110c61de1197cb - SHA-1:
2e8f3ee6aebc80ebef1532b83cb5fdc060dc48c6 - MD5:
dcff6048ff262dbb7a7da70e0bbe50d9 - ssdeep:
1536:sGFNafnyKu0pXizgeBdjou3r1XYGpgiz7MZV:JFNnDzJBVou35XY8giG - TLSH:
T19A34AEF39163EE4C3A8BBF436DBB25489049D3886636976405887B6DC4BC67C7F009A1 - Submitted as: wejafutoreninebozo.pdf
- File type: pdf · Size: 56448 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=fda%20staff%20manual%20guide%202020, https://uploads.strikinglycdn.com/files/5d71f607-4991-4dc6-8430-0f4fa6658449/51701514880.pdf, https://uploads.strikinglycdn.com/files/7abe52ef-aedc-44a8-a569-d6dce0f37a4b/duzededevera.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=fda%20staff%20manual%20guide%202020
- https://s3.amazonaws.com/xanebavifamopez/ganepezuvizaketa.pdf
- https://s3.amazonaws.com/mijedusovineti/lonely_planet_paris.pdf
- https://s3.amazonaws.com/subud/pexirajoxutuwusixan.pdf
- https://s3.amazonaws.com/henghuili-files2/72663620584.pdf
- https://uploads.strikinglycdn.com/files/5d71f607-4991-4dc6-8430-0f4fa6658449/51701514880.pdf
- https://uploads.strikinglycdn.com/files/7abe52ef-aedc-44a8-a569-d6dce0f37a4b/duzededevera.pdf
- https://uploads.strikinglycdn.com/files/c9cfd56a-e73c-4c31-87ca-22abafa173b2/literary_essay_mentor_texts.pdf
- https://uploads.strikinglycdn.com/files/23753613-0c58-4efd-a629-ca53fa9ba4f5/8599288089.pdf
- https://uploads.strikinglycdn.com/files/96fa95b6-c788-44ee-9a36-6c6bc1c33850/99611611174.pdf
- https://uploads.strikinglycdn.com/files/df42bbe2-649a-488a-ac4c-4d20e97c8997/tapeboxodefuta.pdf
- https://uploads.strikinglycdn.com/files/daa041ff-6b0b-40ac-a5f4-d6943230005e/97830238899.pdf
- https://s3.amazonaws.com/fovezewi/sense_and_antisense_strands_of_dna.pdf
- https://s3.amazonaws.com/mibiwivanetuj/jesiv.pdf
- https://s3.amazonaws.com/xanebavifamopez/92468426639.pdf
- https://uploads.strikinglycdn.com/files/96b38983-26f2-4026-aa37-476f387a5e66/xixapodupebarenevolebemiz.pdf
- https://uploads.strikinglycdn.com/files/20864a5c-fa1e-4a61-b121-05b90de3566d/kadanadawuzobodiw.pdf
- https://uploads.strikinglycdn.com/files/ad531893-afda-41f2-86ad-f03ec08f1531/sunivepuwofewokelafesi.pdf
- https://uploads.strikinglycdn.com/files/d2530538-a349-45c3-84bc-3807e3e51634/wojipuluj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report