SUSPICIOUS — jenupexi.pdf
SUSPICIOUS — jenupexi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8222e44585f66760efd2de7df61424791e19ad4fbe5341110314dd03885799f1 - SHA-1:
0ee93ac1dc34513367188263b1b43bae785579d4 - MD5:
071623681b4d334a5e128388f1cf1abe - ssdeep:
768:VgGzpD0pZOfaajjS7f+4sPwdku5De7KBMihXBcCzn+2zZu4VKS5KwLqr0+zY8fcP:GGFgpZ47ULBcGzwbS5KwLq4QfcS7y - TLSH:
T13B319DF310A7EC8C3A4BAF536EAB12D96549C78C6036A790589C772CC17C6FCAE40552 - Submitted as: jenupexi.pdf
- File type: pdf · Size: 41756 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=time%20warner%20cable%20error%20code%20s0600, https://cdn-cms.f-static.net/uploads/4371261/normal_5f8988e9caa97.pdf, https://cdn-cms.f-static.net/uploads/4370087/normal_5f8a06aa2c0fa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=time%20warner%20cable%20error%20code%20s0600
- https://cdn-cms.f-static.net/uploads/4371261/normal_5f8988e9caa97.pdf
- https://cdn-cms.f-static.net/uploads/4370087/normal_5f8a06aa2c0fa.pdf
- https://cdn-cms.f-static.net/uploads/4381551/normal_5f8b2aab89483.pdf
- https://cdn.shopify.com/s/files/1/0434/2536/6165/files/vijayanagar_and_bahmani_kingdom.pdf
- https://cdn.shopify.com/s/files/1/0439/4916/2654/files/pagilajafuxejitejufubuva.pdf
- https://cdn.shopify.com/s/files/1/0428/8266/2553/files/lekaxulumanifawulizovoxos.pdf
- https://cdn.shopify.com/s/files/1/0497/6050/1921/files/slow_shopping_thrapie.pdf
- https://cdn.shopify.com/s/files/1/0499/9086/0950/files/vafumagi.pdf
- https://cdn.shopify.com/s/files/1/0496/0105/2836/files/first_alert_smoke_and_carbon_alarm_manual_pc900.pdf
- https://cdn.shopify.com/s/files/1/0502/1673/0799/files/19003362398.pdf
- https://cdn.shopify.com/s/files/1/0479/8306/7292/files/cabell_county_courthouse_birth_certificate.pdf
- https://cdn.shopify.com/s/files/1/0500/9470/2763/files/lonowonomifimoz.pdf
- https://cdn.shopify.com/s/files/1/0503/3879/1582/files/download_novel_wuthering_heights_bahasa_indonesia.pdf
- https://uploads.strikinglycdn.com/files/ef828497-6cda-4d24-8f5e-78b3ccad788c/18899102497.pdf
- https://uploads.strikinglycdn.com/files/c92151d8-4cda-41ed-a734-f02a33625f59/regiwufojikagag.pdf
- https://cdn-cms.f-static.net/uploads/4368237/normal_5f8ce05fd3d85.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f8eb3293e36c.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.ask.charter.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report