SUSPICIOUS — jovazifura.pdf
SUSPICIOUS — jovazifura.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9927618ca2109fe2d045aba17ea8dca4d5eff480aff4bb25677f2cf489f1e484 - SHA-1:
2f9e6a29e502c06e72951414f371e547c2ffe8c6 - MD5:
fe524bba2b343b896dbcc2450cf71c15 - ssdeep:
768:7gGzpDV5bkg5CLhl22rtb+ggsq8oKA68XpMxGiN35zSUr4BRyC2SqU5EbO0JLzl5:EGFRVkBmj2xGil5zjrqRyBliE1vljcTo - TLSH:
T14A328DF350A7EE4C7A87AF53ADBA65A8114AC7486132D760448C772CC4BC7BD6F01A50 - Submitted as: jovazifura.pdf
- File type: pdf · Size: 45999 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=o%20que%20%C3%A9%20entropia%20pdf, https://cdn-cms.f-static.net/uploads/4412592/normal_5f93ab2bcfdac.pdf, https://cdn.shopify.com/s/files/1/0503/2417/7093/files/curso_de_economia_gratis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=o%20que%20%C3%A9%20entropia%20pdf
- https://cdn-cms.f-static.net/uploads/4412592/normal_5f93ab2bcfdac.pdf
- https://cdn.shopify.com/s/files/1/0503/2417/7093/files/curso_de_economia_gratis.pdf
- https://uploads.strikinglycdn.com/files/5a66f602-236e-46b9-a60b-29721d57633b/bc_rich_warbeast_trace_bass.pdf
- https://cdn-cms.f-static.net/uploads/4381091/normal_5f93bbf7c3bf4.pdf
- https://uploads.strikinglycdn.com/files/5b06a422-04bd-4d3c-9828-0f7d081c1901/75212561436.pdf
- https://cdn-cms.f-static.net/uploads/4417140/normal_5f961218742d6.pdf
- https://cdn-cms.f-static.net/uploads/4409092/normal_5f9302b1383d6.pdf
- https://cdn-cms.f-static.net/uploads/4411245/normal_5f979d0018654.pdf
- https://cdn.shopify.com/s/files/1/0501/2904/3651/files/xanathar_guide_to_everything_anyflip.pdf
- https://cdn-cms.f-static.net/uploads/4373999/normal_5f9341bfaf525.pdf
- https://cdn-cms.f-static.net/uploads/4366995/normal_5f872c4bdda96.pdf
- https://cdn-cms.f-static.net/uploads/4376374/normal_5f9448b59f92a.pdf
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f8e0a04e044b.pdf
- https://cdn-cms.f-static.net/uploads/4370092/normal_5f89027aed481.pdf
- https://cdn-cms.f-static.net/uploads/4410448/normal_5f96b7f1d3fa5.pdf
- https://cdn-cms.f-static.net/uploads/4392864/normal_5f93d746353f4.pdf
- https://cdn-cms.f-static.net/uploads/4368481/normal_5f9003b598c8f.pdf
- https://uploads.strikinglycdn.com/files/1417d1be-a5ff-4315-98a0-3935315add7f/sepakololupekikolabidovi.pdf
- https://uploads.strikinglycdn.com/files/166bb497-be9d-424a-a79e-f4fb4b73b1e8/bogobiw.pdf
- https://cdn-cms.f-static.net/uploads/4366654/normal_5f8cc855b7a28.pdf
- https://cdn-cms.f-static.net/uploads/4419642/normal_5f95ccf579a8e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report