SUSPICIOUS — gokupejenebimujasuj.pdf
SUSPICIOUS — gokupejenebimujasuj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
31f35711a1537e4f19d96ee4ee1e84fb5e05a55033d9273ccd116772817c35c2 - SHA-1:
181bb267c1286cc1421b03052cc61768df01fbd2 - MD5:
97bd25cb2bc2bf405b9a5a6584c7c64e - ssdeep:
768:xgGzpDbyd+Nazu6HzvqmWsXOF33gCuSjgqqFs2/PL1:CGFvjcbzo3YSjWFs2/PL1 - TLSH:
T131309EF35067ED8C7A8BA7076EEB1069604AC68C6132D95025C83B3DD4BC6FD7E10961 - Submitted as: gokupejenebimujasuj.pdf
- File type: pdf · Size: 39267 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=lean+six+sigma+yellow+belt+study+guide+pdf, https://site-1036956.mozfiles.com/files/1036956/fapelusifuvemaz.pdf, https://site-1036702.mozfiles.com/files/1036702/63667209372.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=lean+six+sigma+yellow+belt+study+guide+pdf
- https://site-1036956.mozfiles.com/files/1036956/fapelusifuvemaz.pdf
- https://site-1036702.mozfiles.com/files/1036702/63667209372.pdf
- https://site-1037859.mozfiles.com/files/1037859/litedimaroneturureditupu.pdf
- https://site-1036799.mozfiles.com/files/1036799/99134908838.pdf
- https://site-1036745.mozfiles.com/files/1036745/97964628282.pdf
- https://cdn.shopify.com/s/files/1/0430/8529/9874/files/68325170241.pdf
- https://cdn.shopify.com/s/files/1/0435/1560/9252/files/universal_hollywood_map.pdf
- https://cdn.shopify.com/s/files/1/0433/3489/3718/files/archero_apk_money_hack.pdf
- https://cdn.shopify.com/s/files/1/0434/5312/0664/files/21297715101.pdf
- https://site-1037055.mozfiles.com/files/1037055/xuwozaxibavi.pdf
- https://site-1037215.mozfiles.com/files/1037215/konidoruzojo.pdf
- https://uploads.strikinglycdn.com/files/e9087e01-3884-45d1-abd0-f5ced7d50154/wiliduvorokuvexifeg.pdf
- https://uploads.strikinglycdn.com/files/35b69cb6-f4b8-4aec-9b8a-3cd2df12461d/jemoneguz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036956.mozfiles.com
- site-1036702.mozfiles.com
- site-1037859.mozfiles.com
- site-1036799.mozfiles.com
- site-1036745.mozfiles.com
- cdn.shopify.com
- site-1037055.mozfiles.com
- site-1037215.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report