SUSPICIOUS — kafidigakijesoreru.pdf
SUSPICIOUS — kafidigakijesoreru.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
23d4d7f562e40dad63270b3ab48c849fc40f5b00248d4059c5dc3b84b19dff30 - SHA-1:
663999fbf8a1ac143de6881a834d3fbc5a2be5e8 - MD5:
70c97e150dbef2c9b33e4318de95279f - ssdeep:
768:DgGzpDrp0eGeFtt5/a2N88xNfeT8s2I4gb3jD3LYmeU7QT/884bH8/bOqbhd:8GFvpDKAs34gbHMmxE/qbH8/bOqbhd - TLSH:
T1FA328CF35093DD4C7ACBAB13AEE7216A9489D7885132E7A0448C372DC4BC76E3E50960 - Submitted as: kafidigakijesoreru.pdf
- File type: pdf · Size: 46514 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=encyclopedia%20of%20monsters%20jeff%20rovin%20pdf, https://cdn-cms.f-static.net/uploads/4374203/normal_5f88f18fd724a.pdf, https://cdn-cms.f-static.net/uploads/4365570/normal_5f87464022b47.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=encyclopedia%20of%20monsters%20jeff%20rovin%20pdf
- https://cdn-cms.f-static.net/uploads/4374203/normal_5f88f18fd724a.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87464022b47.pdf
- https://cdn-cms.f-static.net/uploads/4374178/normal_5f89280d44df7.pdf
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f87100f2f38a.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f892d0649485.pdf
- https://cdn-cms.f-static.net/uploads/4373271/normal_5f88a3fe3b320.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/xomoripaxero.pdf
- https://jumuwubugunitus.weebly.com/uploads/1/3/1/0/131070493/xepak.pdf
- https://mixorone.weebly.com/uploads/1/3/1/4/131438240/622d8784d191f.pdf
- https://cdn-cms.f-static.net/uploads/4369324/normal_5f89b9bfa3a1c.pdf
- https://cdn-cms.f-static.net/uploads/4368742/normal_5f881e92f38e1.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f8921f02022c.pdf
- https://cdn.shopify.com/s/files/1/0481/6024/3879/files/wood_badge_ticket_worksheet_doc.pdf
- https://cdn.shopify.com/s/files/1/0498/1702/6715/files/90817981994.pdf
- https://cdn.shopify.com/s/files/1/0438/3657/1808/files/44949555178.pdf
- https://cdn.shopify.com/s/files/1/0431/5850/3590/files/staar_scoring_guide_2018.pdf
- https://cdn.shopify.com/s/files/1/0481/5768/7959/files/america_the_story_of_us_questions_episode_4.pdf
- https://uploads.strikinglycdn.com/files/64efd7d0-ba1c-4dba-ba99-b8c0fa0b1377/99251183523.pdf
- https://uploads.strikinglycdn.com/files/b6cd8a30-b5f7-426e-983a-d03d54b0d7f5/tojunilulowalud.pdf
- https://uploads.strikinglycdn.com/files/36cbaee1-9b40-4b54-a2e7-4f18388c4a31/96218773534.pdf
- https://uploads.strikinglycdn.com/files/0d7a59f1-5f9a-465c-a99d-0025de1cc372/62428754292.pdf
- https://uploads.strikinglycdn.com/files/b8ebfb89-0f3f-4b81-adbd-9c548aeac3ca/vebilidowosoriderepixuxeb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- xumogimunosu.weebly.com
- jumuwubugunitus.weebly.com
- mixorone.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report