SUSPICIOUS — jaxupukubato.pdf
SUSPICIOUS — jaxupukubato.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2d3abfc750fb7481b128462ded7a0850115f0ac79702c614cdfb29c242f6f90d - SHA-1:
011d835f4fab4863e61180169793ade14b0bdbb5 - MD5:
a8e3672baa61eab6ced7360c2590a8dc - ssdeep:
768:EgGzpDUpKmAz71MI3BVjvLOg6kTQLBVfIZ5N8QXR1cv2LLXONxz0vdDi:xGFgpKDH1/eWTQAZ5N8QXMv2f+N6dDi - TLSH:
T19A327DF310E7ED4C768F5F47AEAB1499A48AD389A036D760048D672CC4BC6ED6F00A51 - Submitted as: jaxupukubato.pdf
- File type: pdf · Size: 45843 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=hot%20head%20burrito%20menu%20pdf, https://uploads.strikinglycdn.com/files/ef7a6dd4-096c-4d5d-92c5-6c1c9507dc74/gogotubuda.pdf, https://uploads.strikinglycdn.com/files/8489e763-cc4e-458e-86dd-f6bee53249f4/28164047892.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=hot%20head%20burrito%20menu%20pdf
- https://uploads.strikinglycdn.com/files/ef7a6dd4-096c-4d5d-92c5-6c1c9507dc74/gogotubuda.pdf
- https://uploads.strikinglycdn.com/files/8489e763-cc4e-458e-86dd-f6bee53249f4/28164047892.pdf
- https://uploads.strikinglycdn.com/files/100fd898-bf1f-49c1-9a4e-cc302fc9cca9/86854763253.pdf
- https://uploads.strikinglycdn.com/files/61298b69-99de-488a-910a-86a39c8784fd/88684784251.pdf
- https://uploads.strikinglycdn.com/files/963e9186-7b43-44e1-ba2e-0b5cdd827295/8303716062.pdf
- https://cdn-cms.f-static.net/uploads/4393044/normal_5f9041f5e5694.pdf
- https://cdn-cms.f-static.net/uploads/4367310/normal_5f8bde6004b7e.pdf
- https://cdn-cms.f-static.net/uploads/4371010/normal_5f8fda2750082.pdf
- https://cdn-cms.f-static.net/uploads/4368759/normal_5f87ff5f52066.pdf
- https://cdn-cms.f-static.net/uploads/4371246/normal_5f8f8f6056ce4.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/vifotatilaw.pdf
- https://wirukibit.weebly.com/uploads/1/3/0/9/130969322/9699126.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/c25f730.pdf
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/zubobaratezodojuleri.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/7805117.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/3355978.pdf
- https://xogexemufak.weebly.com/uploads/1/3/1/4/131437987/9afa3facd.pdf
- https://vufevilasok.weebly.com/uploads/1/3/4/3/134314299/81ca275.pdf
- https://s3.amazonaws.com/wonoti/90024307006.pdf
- https://s3.amazonaws.com/sugaguxagu/personal_statement_for_scholarship_application_examples.pdf
- https://s3.amazonaws.com/henghuili-files/41491646429.pdf
- https://s3.amazonaws.com/memul/container_dimensions_metric.pdf
- https://s3.amazonaws.com/susopuzupure/18364225845.pdf
- https://uploads.strikinglycdn.com/files/780357cf-8730-40b6-a2e0-23d51b5d141a/53937155205.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- fijojonibiw.weebly.com
- wirukibit.weebly.com
- gevafitasib.weebly.com
- kupugaxome.weebly.com
- mogilifus.weebly.com
- gimejexoxixaza.weebly.com
- xogexemufak.weebly.com
- vufevilasok.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report