SUSPICIOUS — jomezusuxelatamijap.pdf
SUSPICIOUS — jomezusuxelatamijap.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a3ac8b48cb95087e7e30029ab3db2ecc603b8014c8441561e41f67c1885db2cb - SHA-1:
c54f4ca3c3951616b9f1d4ead6674cd99a1495bb - MD5:
904d94a0d2d4b14d1dbfc612534da650 - ssdeep:
768:1gGzpDcDuCkJ8BQAziPLyfEnSHlpULng0lNMEZz8ZdBdMh2gW7Mtd4gDwFlklKA+:mGF4Dm9+fEcgLg0lNMEYdByhDBd4gy00 - TLSH:
T19332AEF3519BEDCC3A8BAB07ADE610896196D3893133D66049D8772CC0B83BD6E10952 - Submitted as: jomezusuxelatamijap.pdf
- File type: pdf · Size: 45549 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=bay+area+buggs+gta+5+lspdfr, http://bifumowo.annegloag.net/uploads/1/3/1/6/131637352/sejasivune-wejupakomufabus.pdf, http://files.magdaslens.com/uploads/1/3/2/6/132681826/5740731.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=bay+area+buggs+gta+5+lspdfr
- http://bifumowo.annegloag.net/uploads/1/3/1/6/131637352/sejasivune-wejupakomufabus.pdf
- http://files.magdaslens.com/uploads/1/3/2/6/132681826/5740731.pdf
- http://dujur.cherylhodges.com/uploads/1/3/0/8/130815582/1898403.pdf
- http://rawowoli.myjmanradio.com/uploads/1/3/0/9/130969744/ruxanifa_duxamomogukap.pdf
- http://jomafesek.lagalaxyschool.com/uploads/1/3/1/3/131384709/zejilaxapaxaviles.pdf
- http://files.3lionsfarncombe.com/uploads/1/3/0/9/130969750/8687977.pdf
- http://gimowup.notoscatering.com/uploads/1/3/1/0/131070317/5d5949.pdf
- http://files.maxxxwar.com/uploads/1/3/1/0/131070872/merufogedo.pdf
- http://kupiledo.easthollywoodchurch.com/uploads/1/3/1/4/131483234/mijenemaluk.pdf
- http://files.cosanova.org/uploads/1/3/1/3/131398236/fukolajexikiv.pdf
- http://gadevu.thesurreysaddlery.com/uploads/1/3/1/4/131438464/a498eaae.pdf
- http://jowuzakix.nolapartnership.org/uploads/1/3/0/8/130874175/1573426.pdf
- https://cdn.shopify.com/s/files/1/0432/7404/3556/files/sujugodisu.pdf
- https://cdn.shopify.com/s/files/1/0437/0258/3449/files/adobe_reader_classic_2019.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- bifumowo.annegloag.net
- files.magdaslens.com
- dujur.cherylhodges.com
- rawowoli.myjmanradio.com
- jomafesek.lagalaxyschool.com
- files.3lionsfarncombe.com
- gimowup.notoscatering.com
- files.maxxxwar.com
- kupiledo.easthollywoodchurch.com
- files.cosanova.org
- gadevu.thesurreysaddlery.com
- jowuzakix.nolapartnership.org
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report