SUSPICIOUS — jinapakenu-tetug.pdf
SUSPICIOUS — jinapakenu-tetug.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100), attributed to the Emotet family. 3 of 50 detection engines flagged it.
Identification
- SHA-256:
67e8ffdea1c78ba6587a6ae34c50923cea541212ba79ea15a7d6a6a96288c3d5 - SHA-1:
31612a1fd482f70e2bdd9d9ff26506ebb0da9eba - MD5:
8dd6945c08b97ed8a2623dcf766de2e5 - ssdeep:
768:jgGzpDrpM3qUh9+XARnKXF4+jfiPfxeIEumL5UUy+DY1efRBa/K:cGFHpM5UFlOfxeIEumL5jy8kO3a/K - TLSH:
T121318DF380B3ED4C768B9F03ADBA2958954DDA48A132A79055887B2CC8BC37D3F01951 - Submitted as: jinapakenu-tetug.pdf
- File type: pdf · Size: 42972 bytes
- Verdict: suspicious (58/100) · Family: Emotet
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: JPCERT/CC: JPCERT_Emotet
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ggtraff.ru/wb?keyword=best%20cipher%20spells, https://cdn-cms.f-static.net/uploads/4369183/normal_5f87f79c195ec.pdf, https://cdn-cms.f-static.net/uploads/4369903/normal_5f8808cf49a60.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=best%20cipher%20spells
- https://cdn-cms.f-static.net/uploads/4369183/normal_5f87f79c195ec.pdf
- https://cdn-cms.f-static.net/uploads/4369903/normal_5f8808cf49a60.pdf
- https://cdn-cms.f-static.net/uploads/4367920/normal_5f88bc675060d.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f870bb17a8c5.pdf
- https://site-1042992.mozfiles.com/files/1042992/fun_for_movers_4th_edition_vk.pdf
- https://site-1036783.mozfiles.com/files/1036783/duzorujuweviju.pdf
- https://site-1038595.mozfiles.com/files/1038595/51369041820.pdf
- https://site-1043248.mozfiles.com/files/1043248/16091478643.pdf
- https://cdn-cms.f-static.net/uploads/4367290/normal_5f88662b145cb.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f87fdcc75578.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/37288358.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/16dfa150.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dekegu.pdf
- https://dojudiwoju.weebly.com/uploads/1/3/1/4/131406456/5106608.pdf
- https://zuxuzesis.weebly.com/uploads/1/3/1/4/131438019/4675241.pdf
- https://uploads.strikinglycdn.com/files/45110868-28e1-42c7-a3f0-1b90079b92a6/xafosegedewopogivid.pdf
- https://uploads.strikinglycdn.com/files/aae0e62a-1301-4314-97cf-cc0d2f8b3151/35493412775.pdf
- https://uploads.strikinglycdn.com/files/c11c02b7-44a0-48df-a330-b360182caf54/favonelokofazofurotika.pdf
- https://uploads.strikinglycdn.com/files/1af324a4-5a54-4291-9858-f74aeb89eb37/lobipefobibig.pdf
- https://uploads.strikinglycdn.com/files/595ba215-a006-4c17-9e1b-de1e99b5b958/29095533279.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1042992.mozfiles.com
- site-1036783.mozfiles.com
- site-1038595.mozfiles.com
- site-1043248.mozfiles.com
- vuzevarezevarot.weebly.com
- vozunutav.weebly.com
- bedizegoresupa.weebly.com
- dojudiwoju.weebly.com
- zuxuzesis.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
More Emotet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report