SUSPICIOUS — jomofilek_navit.pdf
SUSPICIOUS — jomofilek_navit.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
5612c07d417ce4788008e629e315dc5433f031d90f6df4cfd69a3b78fbb9d585 - SHA-1:
a5c10bae441c9fa91ab2b8f950cca57d38dd0032 - MD5:
96d7b5ca4c7bae84ed5034b780554242 - ssdeep:
768:agGzpDvpTSt8lumByw/xe7eTVDZS9aIzguR5t7X4jeYp6+1rRqUjF1RTtleaLmT:HGFLpkjt7AJp6mro4F7HeaST - TLSH:
T1A7339FF31097EC4D3B8EAF17ADEB15ACA04DC68D603696501488772DD4B86ED7F10A60 - Submitted as: jomofilek_navit.pdf
- File type: pdf · Size: 48347 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=lisabetta%20da%20messina%20testo%20pdf, https://cdn.shopify.com/s/files/1/0500/3047/7472/files/graphing_linear_equations_word_problems_worksheet.pdf, https://cdn.shopify.com/s/files/1/0501/6672/6837/files/jiforasijakaxosesas.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=lisabetta%20da%20messina%20testo%20pdf
- https://cdn.shopify.com/s/files/1/0500/3047/7472/files/graphing_linear_equations_word_problems_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0501/6672/6837/files/jiforasijakaxosesas.pdf
- https://cdn.shopify.com/s/files/1/0501/5827/2677/files/liwebizu.pdf
- https://cdn.shopify.com/s/files/1/0480/7481/7693/files/leadership_and_organizational_behavior_in_education.pdf
- https://cdn.shopify.com/s/files/1/0486/6850/8310/files/nash_county_register_of_deeds_index_search.pdf
- https://cdn.shopify.com/s/files/1/0440/2846/1206/files/narration_practice_questions.pdf
- https://cdn.shopify.com/s/files/1/0438/4597/6221/files/infra_arcana_android.pdf
- https://cdn.shopify.com/s/files/1/0435/5280/0929/files/girl_guides_australia_promise_and_law.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f889d0d19d84.pdf
- https://cdn-cms.f-static.net/uploads/4404310/normal_5f935c2957d46.pdf
- https://cdn-cms.f-static.net/uploads/4374703/normal_5f949e5c2f426.pdf
- https://cdn-cms.f-static.net/uploads/4373248/normal_5f8faf2ff39b3.pdf
- https://cdn-cms.f-static.net/uploads/4375507/normal_5f8baccce692a.pdf
- https://cdn-cms.f-static.net/uploads/4368768/normal_5f908b21877c7.pdf
- https://cdn-cms.f-static.net/uploads/4368240/normal_5f92e4ed67e29.pdf
- https://cdn-cms.f-static.net/uploads/4374852/normal_5f90156446783.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f8a6769a6d50.pdf
- https://cdn-cms.f-static.net/uploads/4390999/normal_5f90d78fca349.pdf
- https://cdn-cms.f-static.net/uploads/4368492/normal_5f88fecadd0a7.pdf
- https://cdn-cms.f-static.net/uploads/4374953/normal_5f8cbbbb09699.pdf
- https://cdn-cms.f-static.net/uploads/4370737/normal_5f8eb9e7e79f3.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f87188197484.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report