SUSPICIOUS — pijum.pdf
SUSPICIOUS — pijum.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4ef7b6fd79737f4bfa1b5f0bb4659fd4582f4e89d8724387904f704917f5ef6e - SHA-1:
2ed63860617a302867dfb2f0e511288cae3b3ed6 - MD5:
11b5c98ee8b90de74d882854d063a7e2 - ssdeep:
768:tgGzpDD3QjTH8iPcSm3NoVvq5nXjytQS7SEEGE9+EL+bxaGqm7c5e2MQbqDCQyB6:OGFH313NoNqnXPSLxaGj7c5ZbqyBlY - TLSH:
T1BB349EF300A7ED4C7A8BAB83A97B15A9518AC6893136D7611488772CC47CAFC7F10A50 - Submitted as: pijum.pdf
- File type: pdf · Size: 52561 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=formulas%20de%20dinamica%20rotacional%20pdf, https://cdn-cms.f-static.net/uploads/4366395/normal_5f8905b7c47f7.pdf, https://cdn-cms.f-static.net/uploads/4389586/normal_5f90585906e9e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=formulas%20de%20dinamica%20rotacional%20pdf
- https://cdn-cms.f-static.net/uploads/4366395/normal_5f8905b7c47f7.pdf
- https://cdn-cms.f-static.net/uploads/4389586/normal_5f90585906e9e.pdf
- https://cdn-cms.f-static.net/uploads/4391015/normal_5f8ff9b743bb7.pdf
- https://cdn-cms.f-static.net/uploads/4380076/normal_5f8b3b656bd38.pdf
- https://uploads.strikinglycdn.com/files/aca38d8b-783c-4bc9-9b06-ac459f4ded01/6449383354.pdf
- https://uploads.strikinglycdn.com/files/aa364b30-b525-4027-9bec-384a5a00cda1/engineering_technology_practical_guide_sinhala.pdf
- https://uploads.strikinglycdn.com/files/a9bbb940-7ba5-450c-8f3f-e8a5057d3562/lesikuvavobilewapokiza.pdf
- https://uploads.strikinglycdn.com/files/c5483be8-94a8-4ab7-bbcf-0c15c677b3c9/mezopepekofikuguwolik.pdf
- https://uploads.strikinglycdn.com/files/97d7d0a2-60fc-4c64-837c-de0071b19216/bihar_b._ed_college_list.pdf
- https://uploads.strikinglycdn.com/files/e82bfb93-48a1-467d-90c5-e47eaeb1b6cf/54245012212.pdf
- https://uploads.strikinglycdn.com/files/d5b9f4d2-5128-47ad-996f-887a36dec2f4/rimivatuzajalima.pdf
- https://uploads.strikinglycdn.com/files/1be7af80-11fd-4559-86e7-97aae13e59d7/towutosipex.pdf
- https://s3.amazonaws.com/towakog/aluminium_alloys_lm_series.pdf
- https://s3.amazonaws.com/zobuwubedak/77360317410.pdf
- https://s3.amazonaws.com/tetazino/plantas_de_casas_modernas_tipo_2.pdf
- https://s3.amazonaws.com/tugumeb/materiales_metalicos_ceramicos_polimeros_y_compuestos.pdf
- https://cdn.shopify.com/s/files/1/0431/8163/7794/files/33200267932.pdf
- https://cdn.shopify.com/s/files/1/0429/4557/7116/files/logawijagatu.pdf
- https://cdn.shopify.com/s/files/1/0436/6031/2741/files/wumafetewukomular.pdf
- https://cdn.shopify.com/s/files/1/0266/8190/1253/files/gc_fortnite_gaming.pdf
- https://cdn.shopify.com/s/files/1/0492/4699/4588/files/75532990882.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report