SUSPICIOUS — jitegodegipom.pdf
SUSPICIOUS — jitegodegipom.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
95f373a5ee1c278b6c14e8947e2c028122ae7de2215b137763d5e436f7f83936 - SHA-1:
0506f5375198f3d427ffe6c6fc15750c0a9afb79 - MD5:
6752345bfb1b81d61dddf9103d2b951c - ssdeep:
1536:4GF2QSMJQgIK7zBOi1RZxVQqGISUJg8odIWVPt:VF2NDgIK7dbD/VQqGISUm5vX - TLSH:
T1D635CFF754A7EC4D3B925B03ADAB15982145D3485236E76004C86B7ED07CAFEBE20621 - Submitted as: jitegodegipom.pdf
- File type: pdf · Size: 59700 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=barbarismes+catala+pdf, https://uploads.strikinglycdn.com/files/18e25a20-1474-4593-b0cd-648d26dd8afe/30539129494.pdf, https://uploads.strikinglycdn.com/files/8f4a6936-a44d-424f-97ca-54c3e4232a04/47385151169.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=barbarismes+catala+pdf
- https://uploads.strikinglycdn.com/files/18e25a20-1474-4593-b0cd-648d26dd8afe/30539129494.pdf
- https://uploads.strikinglycdn.com/files/8f4a6936-a44d-424f-97ca-54c3e4232a04/47385151169.pdf
- https://uploads.strikinglycdn.com/files/fe6219f5-115d-4037-87e7-3081d1d0cbff/50890454291.pdf
- https://uploads.strikinglycdn.com/files/933c3a84-3fdb-4a8e-b737-cc7bba49d396/fedazipiburule.pdf
- https://uploads.strikinglycdn.com/files/23fe1c0e-c36d-4d47-bcb1-bae9d0c5575a/rabiraz.pdf
- https://cdn.shopify.com/s/files/1/0427/5693/1751/files/pewage.pdf
- https://cdn.shopify.com/s/files/1/0480/5525/5204/files/dozapaviwexaferuko.pdf
- https://cdn.shopify.com/s/files/1/0440/6912/6309/files/9609828183.pdf
- https://cdn.shopify.com/s/files/1/0429/8565/2375/files/linoz.pdf
- https://cdn.shopify.com/s/files/1/0431/3792/5269/files/91344821693.pdf
- https://site-1037135.mozfiles.com/files/1037135/63668825567.pdf
- https://site-1037029.mozfiles.com/files/1037029/56274928721.pdf
- https://site-1038586.mozfiles.com/files/1038586/wipebubomanila.pdf
- https://site-1037212.mozfiles.com/files/1037212/rakige.pdf
- https://site-1038612.mozfiles.com/files/1038612/kabiganiname.pdf
- https://cdn.shopify.com/s/files/1/0432/8374/2873/files/wasejomedaxide.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/75130531250.pdf
- https://cdn.shopify.com/s/files/1/0429/4072/7463/files/nafilewejax.pdf
- https://cdn.shopify.com/s/files/1/0427/7737/8972/files/how_to_get_free_tiktok_likes_no_human_verification.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1037135.mozfiles.com
- site-1037029.mozfiles.com
- site-1038586.mozfiles.com
- site-1037212.mozfiles.com
- site-1038612.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report