SUSPICIOUS — jalab.pdf
SUSPICIOUS — jalab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1292d4f1fe8e094578a9cd85439306717a097d88ea3b2a0c97218aeb5b394d7f - SHA-1:
dcff85d6ba47a1b75fe47d372ae74ac9fd5dd45f - MD5:
89d3e0dfc48be90e0ca1bebda4085cd3 - ssdeep:
1536:nGFG0GzXQyyWFgjc2LD67Gf5FUmwyqPv:GFGVXQ7WK4262xwZ - TLSH:
T17933BEF350A7DD8C7A8B6B87AAA601596056C3C87037AA7009D8772CC1BC3FD6F11A51 - Submitted as: jalab.pdf
- File type: pdf · Size: 49612 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=natural+navigation+fce+test+1+answer, http://lilew.stitchanddestroy.com/uploads/1/3/1/6/131636746/benupikagokarunekivo.pdf, http://dukewajo.shannonsstudio.com/uploads/1/3/2/6/132683292/9128695.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=natural+navigation+fce+test+1+answer
- http://lilew.stitchanddestroy.com/uploads/1/3/1/6/131636746/benupikagokarunekivo.pdf
- http://dukewajo.shannonsstudio.com/uploads/1/3/2/6/132683292/9128695.pdf
- http://xivovum.triplecrownlacrosse.com/uploads/1/3/1/4/131453558/detax.pdf
- http://kevibuk.pennlawblsa.com/uploads/1/3/1/0/131070301/8201190.pdf
- http://files.pitch2script.com/uploads/1/3/0/9/130969855/tijitanu.pdf
- https://uploads.strikinglycdn.com/files/277d9e0d-9c85-4982-b447-4af9c9f8c919/361385971.pdf
- https://uploads.strikinglycdn.com/files/1d938c7c-79f7-41d2-9c26-1add7c35443d/lofewivelijakaxejuxabazon.pdf
- https://uploads.strikinglycdn.com/files/37c7da9a-e032-44bf-b90a-ff7f287793bd/18025324745.pdf
- https://uploads.strikinglycdn.com/files/4c4b9fcb-1f69-4b6b-bc5a-891d7d0226b4/27043583565.pdf
- https://cdn.shopify.com/s/files/1/0477/0414/6076/files/wiselisu.pdf
- https://cdn.shopify.com/s/files/1/0432/1715/8312/files/86826713861.pdf
- https://cdn.shopify.com/s/files/1/0436/4225/7561/files/mibosagonexesamo.pdf
- https://cdn.shopify.com/s/files/1/0481/4848/0149/files/what_are_the_main_branches_of_oceanography.pdf
- https://cdn.shopify.com/s/files/1/0477/4694/1084/files/school_for_wives_moliere_plot.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- lilew.stitchanddestroy.com
- dukewajo.shannonsstudio.com
- xivovum.triplecrownlacrosse.com
- kevibuk.pennlawblsa.com
- files.pitch2script.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report