SUSPICIOUS — jujewosalik.pdf
SUSPICIOUS — jujewosalik.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
395c79c9995300a7fb828fc095d93fe42ff6df0c9d106f3b2668c613ce184f81 - SHA-1:
895676790a1729d84b84b369c2adf01ac7a83df1 - MD5:
cd2cfd898990dd2fd8acc38f94838b80 - ssdeep:
768:8gGzpD/p503px9oJRaBtczHsg1PHXsY2XE6Y6f14SALs+zrGT42cM2zP/hAXxPXA:ZGFDp0EJRan6M0jzrGKFPJAhVi - TLSH:
T19133BFF3406BED9C7A866B13BCF6115A6089CB8D6176E7A0408C7B6DC4BC2BD7E10451 - Submitted as: jujewosalik.pdf
- File type: pdf · Size: 52049 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=the%20full%20facts%20book%20of%20cold%20reading, https://site-1039180.mozfiles.com/files/1039180/85973443514.pdf, https://site-1043352.mozfiles.com/files/1043352/32491390762.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=the%20full%20facts%20book%20of%20cold%20reading
- https://site-1039180.mozfiles.com/files/1039180/85973443514.pdf
- https://site-1043352.mozfiles.com/files/1043352/32491390762.pdf
- https://site-1043447.mozfiles.com/files/1043447/3715168165.pdf
- https://site-1039878.mozfiles.com/files/1039878/54175826114.pdf
- https://cdn-cms.f-static.net/uploads/4367304/normal_5f87caac70a15.pdf
- https://cdn-cms.f-static.net/uploads/4369504/normal_5f87d1124061e.pdf
- https://cdn.shopify.com/s/files/1/0496/2120/5145/files/being_green_at_ben_and_jerrys_questions.pdf
- https://cdn.shopify.com/s/files/1/0496/6799/7852/files/world_cup_2020_free_download.pdf
- https://cdn.shopify.com/s/files/1/0438/2153/1293/files/cs_lewis_space_trilogy_order.pdf
- https://cdn.shopify.com/s/files/1/0461/8122/0505/files/sony_digital_8_handycam_dcr_trv340_manual.pdf
- https://cdn-cms.f-static.net/uploads/4368504/normal_5f878df339b77.pdf
- https://cdn-cms.f-static.net/uploads/4366664/normal_5f8786cb5c17c.pdf
- https://cdn-cms.f-static.net/uploads/4367311/normal_5f87642c73132.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f87178d402ea.pdf
- https://uploads.strikinglycdn.com/files/51c9c8e8-b833-4dbf-b507-7faeac86c3f8/ribuvikawejefo.pdf
- https://uploads.strikinglycdn.com/files/2dfd7910-23f3-46ff-a26d-8a4ac4b1fc13/wokafezukenufuwewebedif.pdf
- https://uploads.strikinglycdn.com/files/a803a556-d91b-4d7e-9a4c-87a75e10c6f3/15112700850.pdf
- https://uploads.strikinglycdn.com/files/807c7a30-fe11-4abc-b53e-8b39b7fb8403/40907324747.pdf
- https://uploads.strikinglycdn.com/files/ebd2dadc-d8f9-4eb0-b020-955631b52744/gexabaroroxesara.pdf
- https://site-1042453.mozfiles.com/files/1042453/kovopanakixijupunipifoj.pdf
- https://site-1037842.mozfiles.com/files/1037842/26076188914.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- site-1039180.mozfiles.com
- site-1043352.mozfiles.com
- site-1043447.mozfiles.com
- site-1039878.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1042453.mozfiles.com
- site-1037842.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report