SUSPICIOUS — jagijakam.pdf
SUSPICIOUS — jagijakam.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
90e0137f3d0a544c49d01b6f2e6a81ca5197dcde153d7b952dff73c67fdc8f9e - SHA-1:
427626e01c229d65c5d6865d67cfb125af42c272 - MD5:
2aaccd03b480c77832d08e860f0bebff - ssdeep:
768:QgGzpDCEZG1DIj84s+Lwi+VGiWTuHH0RwGJOpqogS2E2hb6+fX9:9GF2WKkNTPRw6OpqogS2EO2eX9 - TLSH:
T171316CF35057EC8C7E8B9743ADAB14AE5089D388A237E360549C7B2DC07C6BD6E10961 - Submitted as: jagijakam.pdf
- File type: pdf · Size: 42201 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=jerry%20coker%20patterns%20for%20jazz%20pdf, https://cdn.shopify.com/s/files/1/0432/6627/7534/files/corona_renderer_tutorial_3ds_max.pdf, https://cdn.shopify.com/s/files/1/0497/8039/2103/files/recover_lost_photos_after_factory_reset_android.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=jerry%20coker%20patterns%20for%20jazz%20pdf
- https://s3.amazonaws.com/felasorarabipis/tigeri.pdf
- https://s3.amazonaws.com/pazifetanegapu/losiroxaki.pdf
- https://s3.amazonaws.com/tizowodifi/xuberivubigemigobadarineg.pdf
- https://s3.amazonaws.com/wenobagupexekap/english_phonetics_practice.pdf
- https://s3.amazonaws.com/henghuili-files/describing_physical_appearance_esl.pdf
- https://cdn.shopify.com/s/files/1/0432/6627/7534/files/corona_renderer_tutorial_3ds_max.pdf
- https://cdn.shopify.com/s/files/1/0497/8039/2103/files/recover_lost_photos_after_factory_reset_android.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/comprehension_worksheet_ks2.pdf
- https://uploads.strikinglycdn.com/files/5ffdb360-a2bc-4941-a537-19b692d1ce72/rusumefuk.pdf
- https://uploads.strikinglycdn.com/files/7854f21d-4fff-42e6-9bc3-14fd8ae5a9e5/gutefurataduteradumafoke.pdf
- https://uploads.strikinglycdn.com/files/30863f43-697c-4fc6-acb3-7e59431f1d1c/21620799519.pdf
- https://uploads.strikinglycdn.com/files/1655acec-591c-4631-bc54-daf8139b78fc/70420985107.pdf
- https://uploads.strikinglycdn.com/files/925f022d-a6aa-460f-8e53-594a23a21b3c/zamuwerijafenes.pdf
- https://uploads.strikinglycdn.com/files/709b5640-49f8-4d55-a20b-af1fb14b8499/wogop.pdf
- https://uploads.strikinglycdn.com/files/b3f40c01-e759-4de8-831b-a2f09b3cab48/zonivom.pdf
- https://uploads.strikinglycdn.com/files/3648412d-daa0-4aee-b351-cbbdfe72974c/kusidotijeturujep.pdf
- https://gijakumode.weebly.com/uploads/1/3/4/3/134306186/38fda2.pdf
- https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/ximimebasoril-tabimotifonud-midaririkem.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/dobod-rifibadaveve.pdf
- https://cdn.shopify.com/s/files/1/0464/5129/4376/files/my_hero_academia_episode_24_funimation.pdf
- https://cdn.shopify.com/s/files/1/0495/7208/5926/files/61869588445.pdf
- https://cdn.shopify.com/s/files/1/0439/5129/2584/files/identity_v_female_dancer_guide.pdf
- https://cdn.shopify.com/s/files/1/0484/7478/3906/files/71421159190.pdf
- https://cdn.shopify.com/s/files/1/0430/8929/7557/files/kudovawazeri.pdf
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- gijakumode.weebly.com
- mijisurux.weebly.com
- natizupasa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report