SUSPICIOUS — jeduxuxorakepapubowiga.pdf
SUSPICIOUS — jeduxuxorakepapubowiga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a6cd24a75fbfc0469deefbdf992ddd622213f1c36f75bed463d3a51e271ddee9 - SHA-1:
9a22f158952ae3dcd35a4dcf3657ec1999e7fd80 - MD5:
f09c8b53b5245ef4fd176bd82859e109 - ssdeep:
768:/gGzpDCpsF3rkTQlZET+VG4lioiFrMRrm8odrnt0PLp+JyEgLiKsP:IGFOp4ie68odztkKy9iKsP - TLSH:
T10932AEF314ABED4D3A87AB03EDEB15591189C38D2136A760949C3A2DD0BC7BD6E10D21 - Submitted as: jeduxuxorakepapubowiga.pdf
- File type: pdf · Size: 46632 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=skills+tracking+sheet, https://uploads.strikinglycdn.com/files/5dbb9fc5-453e-412d-8539-132758bcb6c5/kutexusasuxesiteleki.pdf, https://uploads.strikinglycdn.com/files/9d4cd52c-a3f2-499a-9e7a-6939caaf66ba/tomonowagumajuk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=skills+tracking+sheet
- https://uploads.strikinglycdn.com/files/5dbb9fc5-453e-412d-8539-132758bcb6c5/kutexusasuxesiteleki.pdf
- https://uploads.strikinglycdn.com/files/9d4cd52c-a3f2-499a-9e7a-6939caaf66ba/tomonowagumajuk.pdf
- https://uploads.strikinglycdn.com/files/a89f098b-6f36-4818-93fc-7250d978ab5d/aircraft_propeller_design.pdf
- https://uploads.strikinglycdn.com/files/4b754667-dba5-4db4-9ee1-987f2a9d99f6/gefaradagezusazajuwufas.pdf
- https://uploads.strikinglycdn.com/files/b8b87c30-0246-4c4c-870d-9cf1ff37d647/zebunexega.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/vudodapazepipux_kijemomebegax_velagokotukif.pdf
- https://segakimorepej.weebly.com/uploads/1/3/0/7/130738797/8900005.pdf
- https://cdn.shopify.com/s/files/1/0481/5195/3557/files/tadobesurekavobunimekax.pdf
- https://cdn.shopify.com/s/files/1/0484/8759/6182/files/xosuv.pdf
- https://cdn.shopify.com/s/files/1/0482/8400/8603/files/kerokowexeninoladizugaw.pdf
- https://cdn.shopify.com/s/files/1/0268/8335/8914/files/outlook_app_for_android_keeps_crashing.pdf
- https://cdn.shopify.com/s/files/1/0503/7942/3942/files/3050138366.pdf
- https://cdn.shopify.com/s/files/1/0266/7646/1759/files/86827523305.pdf
- https://uploads.strikinglycdn.com/files/c9c7c9b4-66bf-46ba-8d68-82fd9527e20a/11237536089.pdf
- https://uploads.strikinglycdn.com/files/6af0d61c-cc0e-4796-ae77-253f7ae929c0/kaba_1011_manual.pdf
- https://uploads.strikinglycdn.com/files/470491be-016d-4acc-8079-3a4bde1262cc/virexe.pdf
- https://uploads.strikinglycdn.com/files/86f7487a-9bc3-4ea8-be59-3117e3fea842/dizixejamifefizitonuvojux.pdf
- https://uploads.strikinglycdn.com/files/d7242faf-bf21-497c-888b-c4002d5a0a8e/33133021283.pdf
- https://uploads.strikinglycdn.com/files/c650f4ba-f120-47aa-a8b9-5c62272094d6/pelifonux.pdf
- https://uploads.strikinglycdn.com/files/19888544-58c3-45f3-b00b-b271c05f7f71/25595318467.pdf
- https://uploads.strikinglycdn.com/files/cd3a80a2-1324-4cdc-96ce-1fa0c74e7fbd/28077193107.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- vuxozajuje.weebly.com
- segakimorepej.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report