SUSPICIOUS — kujawejomiwazusunakoni.pdf
SUSPICIOUS — kujawejomiwazusunakoni.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
88c1934122af7c16d036bf6db29d24041bebdfa0381c57408aa5bbdf4bbdae23 - SHA-1:
ad26c7909d59eede715d1336057b9fe0d63896cb - MD5:
309aa023870189cec5a901a89ffbad69 - ssdeep:
768:SgGzpD0PI3WED5T/aAKxDsINdtRaEhvu+7fAfCdr96ATBZF9JSkqOpwCVWBuOst:PGFI/YINdthjsATBZF9skqOpwgauOst - TLSH:
T17A338DF355A7EC8C7B866F076EAA0089508AD28D6132DB6005DC776CD87CAFD7E10A11 - Submitted as: kujawejomiwazusunakoni.pdf
- File type: pdf · Size: 48270 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=problem+of+absenteeism+in+school+pdf, https://cdn.shopify.com/s/files/1/0482/6801/7826/files/36826855984.pdf, https://cdn.shopify.com/s/files/1/0432/0775/3888/files/36724554539.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=problem+of+absenteeism+in+school+pdf
- https://cdn.shopify.com/s/files/1/0482/6801/7826/files/36826855984.pdf
- https://cdn.shopify.com/s/files/1/0432/0775/3888/files/36724554539.pdf
- https://cdn.shopify.com/s/files/1/0467/5852/7139/files/kejijiwefujiwosa.pdf
- https://cdn.shopify.com/s/files/1/0434/2009/0535/files/82693787972.pdf
- https://uploads.strikinglycdn.com/files/ed307e1d-11c9-4b66-9cd2-2f49935a37cd/19328023851.pdf
- https://uploads.strikinglycdn.com/files/6731f7dd-583d-4771-b6b6-e000685526b8/didunanaxemavepevunip.pdf
- https://uploads.strikinglycdn.com/files/950ba1b2-cdd9-4436-b5e9-76835ecbb59e/33792102549.pdf
- https://uploads.strikinglycdn.com/files/269ea1f2-8151-438e-b3a1-419284ad603f/dataxavu.pdf
- https://site-1037106.mozfiles.com/files/1037106/moxipizumob.pdf
- https://site-1037125.mozfiles.com/files/1037125/89398182600.pdf
- https://site-1037011.mozfiles.com/files/1037011/futobikewu.pdf
- https://site-1036772.mozfiles.com/files/1036772/panif.pdf
- https://site-1037164.mozfiles.com/files/1037164/46700567210.pdf
- https://cdn.shopify.com/s/files/1/0429/4174/3263/files/tawefepimikajipipa.pdf
- https://cdn.shopify.com/s/files/1/0439/4595/1400/files/lurokizudunebokula.pdf
- https://cdn.shopify.com/s/files/1/0434/6108/3296/files/cassiopeia_build_guide.pdf
- https://cdn.shopify.com/s/files/1/0431/3173/2132/files/67705894816.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1037106.mozfiles.com
- site-1037125.mozfiles.com
- site-1037011.mozfiles.com
- site-1036772.mozfiles.com
- site-1037164.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report