SUSPICIOUS — pojofasowefeko.pdf
SUSPICIOUS — pojofasowefeko.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
3f53842f42cbf3627c80fe819441b33f8142d3f6d8a08877171318718db67948 - SHA-1:
b7ab0308304acb7373d867f1532ca5f0991c9fc6 - MD5:
0052c59d3ce21fff6fb211b3e60229e6 - ssdeep:
768:jgGzpDXpWVgU7kNLwJbmcCzghsT845odBM1nT7o3nZiTITSTdr4NxH:cGFbpcwNLwJbYzgIe3MJ7oXMkOr4NxH - TLSH:
T12033AEB35163DE987AC6AF03ADE715496045DA4C6032F77058C97B6D887C3FC2E50922 - Submitted as: pojofasowefeko.pdf
- File type: pdf · Size: 48086 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=top+gear+s13e05+autostrada, https://cdn.shopify.com/s/files/1/0488/1547/2805/files/pokemon_white_cheats_openemu.pdf, https://cdn.shopify.com/s/files/1/0480/0515/2917/files/home_depot_kronos.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=top+gear+s13e05+autostrada
- https://cdn.shopify.com/s/files/1/0488/1547/2805/files/pokemon_white_cheats_openemu.pdf
- https://cdn.shopify.com/s/files/1/0480/0515/2917/files/home_depot_kronos.pdf
- https://cdn.shopify.com/s/files/1/0484/9840/9622/files/nidasote.pdf
- https://uploads.strikinglycdn.com/files/a63baea5-164a-4d23-848d-64d6ad73ddb1/nofuzarakufanesis.pdf
- https://site-1036858.mozfiles.com/files/1036858/melawinunivudumejas.pdf
- https://site-1039147.mozfiles.com/files/1039147/32594110080.pdf
- https://uploads.strikinglycdn.com/files/4e06fca7-3a3d-4c42-ba24-8b9fe2b4bf86/sawumeka.pdf
- https://uploads.strikinglycdn.com/files/4e6cb01e-6593-437c-b9de-51d207987152/35581700308.pdf
- https://uploads.strikinglycdn.com/files/c4b9a9d7-ffb6-47c1-aa77-eedd4283727b/sewozezugisanitirurupabi.pdf
- https://uploads.strikinglycdn.com/files/f5fb7c16-2346-442a-b864-1861aad79421/fimodifudeduzaxogagiseso.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1036858.mozfiles.com
- site-1039147.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report