SUSPICIOUS — jogafuwudum.pdf
SUSPICIOUS — jogafuwudum.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
706e8902ebc1fb0fab5db4bd7c5bd889229c90689beaa2ecb4f4606514c25c3c - SHA-1:
04682a91b26e44c01825b40ff1cf9f811689134c - MD5:
39e4bcff1ed6efa9620e8ef79b21c83b - ssdeep:
768:RgGzpDXPWqnBZtDyg//LRDjkbBY1A8MpzEfl8gygzoD5Mznq2S0GAUrbV:iGFbpjR0W1AB5Ml8gPt7hS0GAU/V - TLSH:
T1D432B0F75057EC8C7A8E5B4369A70088A408D68CB132E76451C97BBCC57C7FCAE14662 - Submitted as: jogafuwudum.pdf
- File type: pdf · Size: 46332 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=encyclopedia+judaica+vol+19+pdf, https://cdn.shopify.com/s/files/1/0486/0811/6901/files/ufc_207_live_free_stream.pdf, https://cdn.shopify.com/s/files/1/0434/3152/6557/files/surilupirene.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=encyclopedia+judaica+vol+19+pdf
- https://cdn.shopify.com/s/files/1/0486/0811/6901/files/ufc_207_live_free_stream.pdf
- https://cdn.shopify.com/s/files/1/0434/3152/6557/files/surilupirene.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/zututekafufefosapebuk.pdf
- https://uploads.strikinglycdn.com/files/3f9f1c6c-a7b5-4fee-94c2-8424677345e4/xaputofu.pdf
- https://uploads.strikinglycdn.com/files/49fd8971-9b07-4b68-ba5f-6d4111c38b7e/99196120299.pdf
- https://site-1037260.mozfiles.com/files/1037260/14953345466.pdf
- https://site-1036783.mozfiles.com/files/1036783/49519320180.pdf
- https://cdn.shopify.com/s/files/1/0428/8544/7833/files/61589746805.pdf
- https://cdn.shopify.com/s/files/1/0433/0009/4112/files/33572903296.pdf
- https://cdn.shopify.com/s/files/1/0428/9619/5737/files/westworld_theme_sheet_music_easy.pdf
- https://cdn.shopify.com/s/files/1/0437/4301/9159/files/bubble_sheet_lahore_board.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1037260.mozfiles.com
- site-1036783.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report