SUSPICIOUS — jigosefogiw.pdf
SUSPICIOUS — jigosefogiw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
3bfe5976168d28503d30e7653b7b85f8b74e4c71ea1a8a3f6354cc915d46692b - SHA-1:
0e498a58d6b8a0cd2cd5bdbf530da1801d869640 - MD5:
4592e638408152b5245051c0d2ee744a - ssdeep:
1536:uGFIMpSwwanJHU7+kRFqxbvLALBsJiw4OK78:XFIepZxbzALKUOl - TLSH:
T1CE33AFF3109BED4C3A8AAB037DA51559A149DB8C3173A660449C773DC0BC2BD7E84E62 - Submitted as: jigosefogiw.pdf
- File type: pdf · Size: 50634 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=network+backup+with+bacula+how-+to+pdf, https://uploads.strikinglycdn.com/files/eaa216d5-b4d4-4a33-90a8-7ecffa9d4b30/xigob.pdf, https://uploads.strikinglycdn.com/files/f858cb4e-9b7d-4b74-80bc-a923a36b7a1e/kokiwefisiremeja.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=network+backup+with+bacula+how-+to+pdf
- https://uploads.strikinglycdn.com/files/eaa216d5-b4d4-4a33-90a8-7ecffa9d4b30/xigob.pdf
- https://uploads.strikinglycdn.com/files/f858cb4e-9b7d-4b74-80bc-a923a36b7a1e/kokiwefisiremeja.pdf
- https://uploads.strikinglycdn.com/files/ededfda9-9424-4da4-91ae-ae0fd8a6d4f1/jevogowuse.pdf
- https://uploads.strikinglycdn.com/files/c00c4302-07cb-415c-af65-3287423b3c55/gozugamefujezebako.pdf
- https://uploads.strikinglycdn.com/files/a2cfd438-b21b-4501-bf77-8e3857cfc77f/85653343800.pdf
- https://uploads.strikinglycdn.com/files/757ee19a-3d58-457a-89f1-c849cfa039b6/96516510563.pdf
- https://uploads.strikinglycdn.com/files/9099cd7b-83bf-4729-ab6b-e9910c88de4e/vijaluxabopuxavaxemaxuve.pdf
- https://uploads.strikinglycdn.com/files/18c503cf-cd88-48ff-bc37-9030c9d7d058/vuwitaripu.pdf
- https://cdn.shopify.com/s/files/1/0463/2500/6497/files/29534986384.pdf
- https://cdn.shopify.com/s/files/1/0438/4142/1472/files/apple_mobile_device_support_windows_vista.pdf
- https://cdn.shopify.com/s/files/1/0430/3863/8241/files/psychological_assessment_referral_form.pdf
- https://cdn.shopify.com/s/files/1/0467/9951/9893/files/punctuation_marks_guide.pdf
- https://cdn.shopify.com/s/files/1/0433/8316/0995/files/test_de_autolesion.pdf
- https://uploads.strikinglycdn.com/files/fcda1215-3f99-4773-8631-3c30b651c644/45850487464.pdf
- https://uploads.strikinglycdn.com/files/2409b0ef-d524-4ae1-abf8-0173bf1e7ff2/jefalupapizotokagikinaro.pdf
- https://uploads.strikinglycdn.com/files/4a477503-0bae-45bc-88a6-4cff5deba4e7/38908283494.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report