SUSPICIOUS — jibifukolegipew.pdf
SUSPICIOUS — jibifukolegipew.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
70c1732144af93389ae5db7e3bc9af487627ecef318b0e35adfb3ca714bf25ce - SHA-1:
a508610ef891c2ee189503db7bcf0e650b9083b3 - MD5:
e977652ea38a3876d28602cbdd6cfe50 - ssdeep:
768:0gGzpD03bXKY3e0mtbWpgEm1mPdHhqg11T9XMF4TP7BDCm7HB15iJcbK+Og9IZ1/:BGFwLvg01lvTPFDCm7HB15iqbK7cIZ1/ - TLSH:
T1A1329DF325C7DC4C7B8B9F039DAB1129A08AC34D61769790548C2B2CD0BCAFD6E40961 - Submitted as: jibifukolegipew.pdf
- File type: pdf · Size: 45014 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=tutorial%20google%20groups%20pdf, https://cdn-cms.f-static.net/uploads/4380226/normal_5f8b4ad1a4971.pdf, https://cdn-cms.f-static.net/uploads/4365598/normal_5f8762416ea93.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=tutorial%20google%20groups%20pdf
- https://cdn-cms.f-static.net/uploads/4380226/normal_5f8b4ad1a4971.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f8762416ea93.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8704621f8d1.pdf
- https://cdn-cms.f-static.net/uploads/4376369/normal_5f92628d22a1d.pdf
- https://cdn-cms.f-static.net/uploads/4369654/normal_5f905198301cb.pdf
- https://cdn-cms.f-static.net/uploads/4391326/normal_5f9077cdd45d9.pdf
- https://cdn-cms.f-static.net/uploads/4371790/normal_5f89e8df0d555.pdf
- https://cdn-cms.f-static.net/uploads/4378164/normal_5f927b83206c4.pdf
- https://cdn-cms.f-static.net/uploads/4390381/normal_5f8f941d84cb9.pdf
- https://uploads.strikinglycdn.com/files/225c38d7-9685-4fe1-a5a3-cd3775daf4c8/guliveraduxunufubef.pdf
- https://uploads.strikinglycdn.com/files/9a701540-af31-458d-b6e5-5579d8d73828/67125619725.pdf
- https://uploads.strikinglycdn.com/files/397abf78-9690-475e-b7a4-7b240ba7de5e/jegejifikaderuxusaxoxis.pdf
- https://uploads.strikinglycdn.com/files/f91a9f35-c57d-4841-ab90-c92b8b08c650/vampire_diaries_season_6_watch_online_123movies.pdf
- https://s3.amazonaws.com/kavitokolezub/35751296798.pdf
- https://s3.amazonaws.com/bevarolimesale/56425076530.pdf
- https://cdn.shopify.com/s/files/1/0435/0607/3759/files/androidapksfree_google_play_services.pdf
- https://cdn.shopify.com/s/files/1/0482/8122/3336/files/nicu_survival_guide_for_parents.pdf
- https://cdn.shopify.com/s/files/1/0481/9622/3133/files/north_states_supergate_ergo.pdf
- https://cdn.shopify.com/s/files/1/0498/2118/8251/files/prokaryote_cell_coloring_worksheet_answers.pdf
- https://cdn-cms.f-static.net/uploads/4386848/normal_5f91733d851b1.pdf
- https://cdn-cms.f-static.net/uploads/4366633/normal_5f8f075ad9b12.pdf
- https://cdn-cms.f-static.net/uploads/4393776/normal_5f8f6dec3e8b2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report