SUSPICIOUS — nojenaborexaxijekifabaxa.pdf
SUSPICIOUS — nojenaborexaxijekifabaxa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
0fceab60401483444079188f940cfba1a03dd38f1edc9c9b9c6a988a1a9a78e2 - SHA-1:
62e02b629e89ac37d50a84314638a37a989d5287 - MD5:
ac99900d6bc9be5e2edcc6d0725d96e7 - ssdeep:
768:igGzpDZloWR303/54dc3ydh96KZJc0P5CdEX5ndICWaRAIgssufG52bT:/GFVlQ4P8dEXrICWlI5sufG52bT - TLSH:
T11B34B0F36197ED8C66CBAB13ADAA0409A016854D7237D7A024C87B3CC97C6FC5E15E50 - Submitted as: nojenaborexaxijekifabaxa.pdf
- File type: pdf · Size: 53497 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=iso+14000+nissan, https://uploads.strikinglycdn.com/files/cd357400-890d-4932-a7d3-6d167a70adcd/54839818500.pdf, https://uploads.strikinglycdn.com/files/841e8b2c-a2a6-4b25-b29d-a815c369f242/52713864634.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=iso+14000+nissan
- https://uploads.strikinglycdn.com/files/cd357400-890d-4932-a7d3-6d167a70adcd/54839818500.pdf
- https://uploads.strikinglycdn.com/files/841e8b2c-a2a6-4b25-b29d-a815c369f242/52713864634.pdf
- https://uploads.strikinglycdn.com/files/d8fe8ca5-b3fa-4026-881f-06f801612efe/parekutofidugisukibo.pdf
- http://files.cahabanewmedia.com/uploads/1/3/2/6/132681657/letisosofudade.pdf
- http://files.tamueventing.com/uploads/1/3/0/7/130739684/nobapipaxano-petagesezetusi-sarevavuf.pdf
- https://cdn.shopify.com/s/files/1/0435/7039/7352/files/93169151153.pdf
- https://cdn.shopify.com/s/files/1/0484/6249/5894/files/ai_persona_4_reddit.pdf
- https://site-1038334.mozfiles.com/files/1038334/sedetezilamibutenaruna.pdf
- https://site-1040002.mozfiles.com/files/1040002/nowemokemuwutobinaj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.cahabanewmedia.com
- files.tamueventing.com
- cdn.shopify.com
- site-1038334.mozfiles.com
- site-1040002.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report