SUSPICIOUS — juxibagunu.pdf
SUSPICIOUS — juxibagunu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
76c1999053df3d9ddf3b6667c6e2698494739e6457edbfc877bf55cb93a040e1 - SHA-1:
0993b8c0f0d53bb00fda5f80912af78a2536bca2 - MD5:
7cb7bee2017b83f258318154225b4d44 - ssdeep:
768:sgGzpD0pvy9n1gQoswem8aV56F7aQoMNtsWNjxkwEsGXDjXQKRL:pGFgpsoj8F/VNJNiw32XQKRL - TLSH:
T109328DF350A7ED9C7A8BAB035AEA0169114DD38C6037E7645CC8772DC4AC5ED7E20861 - Submitted as: juxibagunu.pdf
- File type: pdf · Size: 44466 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=drown%20junot%20diaz%20pdf%20download, https://uploads.strikinglycdn.com/files/383d71e0-c6e2-4639-b65c-3c7379cbf5d5/78281901352.pdf, https://uploads.strikinglycdn.com/files/c37c71e3-e2a5-4254-a3e2-1fff92b954f4/61416816451.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=drown%20junot%20diaz%20pdf%20download
- https://uploads.strikinglycdn.com/files/383d71e0-c6e2-4639-b65c-3c7379cbf5d5/78281901352.pdf
- https://uploads.strikinglycdn.com/files/c37c71e3-e2a5-4254-a3e2-1fff92b954f4/61416816451.pdf
- https://uploads.strikinglycdn.com/files/44a18572-4598-4a77-8d80-2518ee1e68f8/53928791452.pdf
- https://uploads.strikinglycdn.com/files/a54c7930-bd69-4489-bfc3-1dbaf09fef9f/kegotivuvetuselixa.pdf
- https://uploads.strikinglycdn.com/files/6e6093fb-4734-4daa-a023-82b7b8a88b91/75418883540.pdf
- https://uploads.strikinglycdn.com/files/c64f0cbf-bb5f-49a4-86bd-b1a206c21831/roributuf.pdf
- https://uploads.strikinglycdn.com/files/dd2a7c4f-77ee-4e5f-8927-162b20721ba4/muselabutujamurunoderekex.pdf
- https://uploads.strikinglycdn.com/files/929e085d-c34b-4984-9f6b-2ca43808b8f4/damomalo.pdf
- https://uploads.strikinglycdn.com/files/1d74b9c4-ef47-48fa-90ba-767747d701b7/55705761562.pdf
- https://uploads.strikinglycdn.com/files/5bb6d0ef-d9dc-46fd-a15f-176090e7280d/52812201853.pdf
- https://cdn.shopify.com/s/files/1/0496/1543/7977/files/24473586026.pdf
- https://cdn.shopify.com/s/files/1/0437/7480/4126/files/86293497115.pdf
- https://cdn.shopify.com/s/files/1/0430/9506/4733/files/41770681852.pdf
- https://cdn.shopify.com/s/files/1/0430/3139/6501/files/vupubumibidev.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/resojafon-zekuni-sudeviganima.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/e4985a4.pdf
- https://uploads.strikinglycdn.com/files/b42948a9-84c7-40c9-a643-ada87ed0a9a1/2804397545.pdf
- https://uploads.strikinglycdn.com/files/319a9357-0bcd-4049-9d94-9a0eb6826650/xexorenajajexodabuto.pdf
- https://uploads.strikinglycdn.com/files/90c57116-6fe2-4112-ac7e-036ecf518c42/dodetibabopabum.pdf
- https://uploads.strikinglycdn.com/files/e1de3169-1f69-4e14-b3a8-20f0bfee9b48/temupabuz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- fuparududewon.weebly.com
- riragojefo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report