SUSPICIOUS — japagenox.pdf
SUSPICIOUS — japagenox.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8f7f0d48427bdf49daa11871ad5c2e4d5f44ea5e49681bab1f057ca868a31454 - SHA-1:
0e8ed316b97493ff409f7cfcd7c30591262e5320 - MD5:
3858b799bc34f6aa6fdbc7ae3c3ff6de - ssdeep:
768:tgGzpDde9u0c4Lw33DpLJCTYCsPsIP1XiBZjfAv/PgiSbvLu1tahDfAcAO7qTKn7:OGFBe9uZ4Lw33DpLJCTYCW7SbvLuC1A4 - TLSH:
T1F8327CF351B7ED4C368BCB076EEE3459604ADB4861329A5459883B2CC87C77E7E40A11 - Submitted as: japagenox.pdf
- File type: pdf · Size: 46541 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/e8b08a87-fdd8-46ee-b2b1-36caf7a126f4/71570064110.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=status+timer+switch+instructions, https://uploads.strikinglycdn.com/files/e8b08a87-fdd8-46ee-b2b1-36caf7a126f4/71570064110.pdf, https://uploads.strikinglycdn.com/files/c0e9ae0b-3a28-4230-8449-6afba89525e3/tisefutaworigivofodob.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=status+timer+switch+instructions
- https://uploads.strikinglycdn.com/files/e8b08a87-fdd8-46ee-b2b1-36caf7a126f4/71570064110.pdf
- https://uploads.strikinglycdn.com/files/c0e9ae0b-3a28-4230-8449-6afba89525e3/tisefutaworigivofodob.pdf
- https://uploads.strikinglycdn.com/files/73e2afe4-a630-450c-9c96-7045b7e3e6c5/wofoxipajuvibisanemijela.pdf
- https://site-1037894.mozfiles.com/files/1037894/fuzomojamunovofaponom.pdf
- https://site-1038470.mozfiles.com/files/1038470/13529613875.pdf
- https://site-1042725.mozfiles.com/files/1042725/1790557304.pdf
- https://cdn.shopify.com/s/files/1/0484/1114/8446/files/58084708780.pdf
- https://cdn.shopify.com/s/files/1/0479/3817/5143/files/34447123580.pdf
- https://cdn.shopify.com/s/files/1/0438/4643/4976/files/what_does_secondary_economic_activity.pdf
- https://cdn.shopify.com/s/files/1/0439/2442/2811/files/linear_algebra_and_its_applications_5th_edition.pdf
- https://uploads.strikinglycdn.com/files/061d584b-7053-400d-9c19-8642919906dc/lamesagorowow.pdf
- https://uploads.strikinglycdn.com/files/1648857b-5f6e-4b22-b0ef-1da66e1fe29c/79782720343.pdf
- https://cdn.shopify.com/s/files/1/0485/0810/8955/files/danididobilibarewon.pdf
- https://cdn.shopify.com/s/files/1/0433/9941/3921/files/human_sexuality_hock_3rd_edition_free_download.pdf
- https://cdn.shopify.com/s/files/1/0499/5540/5992/files/31034283290.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/3cb113af6.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xereromejiv-koxozirusoror-moxonujis.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/caa64.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/jinitorip-bolag.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/lanadez.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1037894.mozfiles.com
- site-1038470.mozfiles.com
- site-1042725.mozfiles.com
- cdn.shopify.com
- keniwuki.weebly.com
- dutitujazekap.weebly.com
- dimaxafazeza.weebly.com
- gimejexoxixaza.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report