SUSPICIOUS — jusiletubi.pdf
SUSPICIOUS — jusiletubi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
ad46145e006b2b2052773055bde20b522dafad693cf12b44f09754dca2ade05c - SHA-1:
33bf10ef0a1799734f7b4a3fa3995b722bec959b - MD5:
bdda69e179fda179db8f3740814526db - ssdeep:
1536:IGFE+CpIXA3JLiPMeuoeWNOQE2jzr75zcEXwS:lFE+IJLikqtNZxj/7hcER - TLSH:
T1B135ADF354ABDD8C7A83EB436CAB1655648ADBC872269B500588772CC4BC7BDBF40940 - Submitted as: jusiletubi.pdf
- File type: pdf · Size: 60794 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=manual%20de%20ireport%205.6%200%20en%20espa%C3%B1ol, https://uploads.strikinglycdn.com/files/1d689bf2-357a-4bb2-8c0f-f622e38f951a/1520962317.pdf, https://uploads.strikinglycdn.com/files/ce02b965-67e7-4180-a22b-4f81d9b5c498/20870453926.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=manual%20de%20ireport%205.6%200%20en%20espa%C3%B1ol
- https://s3.amazonaws.com/jenisozazewubo/sosutonakorarobesun.pdf
- https://s3.amazonaws.com/sugaguxagu/52175619190.pdf
- https://s3.amazonaws.com/mijedusovineti/25433154766.pdf
- https://s3.amazonaws.com/fonazuzixagizir/digital_marketing_ebooks_free_download.pdf
- https://s3.amazonaws.com/zarelusipofox/facebook_graph_api_tutorial.pdf
- https://uploads.strikinglycdn.com/files/1d689bf2-357a-4bb2-8c0f-f622e38f951a/1520962317.pdf
- https://uploads.strikinglycdn.com/files/ce02b965-67e7-4180-a22b-4f81d9b5c498/20870453926.pdf
- https://uploads.strikinglycdn.com/files/51231285-6fd3-4066-9f0c-eef7719130d4/57308969770.pdf
- https://uploads.strikinglycdn.com/files/27dee381-ff90-4122-8ddf-f7c195871e5f/21120789179.pdf
- https://uploads.strikinglycdn.com/files/aa13f4f9-fa3c-47bb-992b-ff8feb26f81d/44310480276.pdf
- https://uploads.strikinglycdn.com/files/85cef041-7af2-4216-a854-817c0bcf47e2/62187953836.pdf
- https://uploads.strikinglycdn.com/files/215d989b-e941-462d-8f56-fa14a046c524/81598181336.pdf
- https://uploads.strikinglycdn.com/files/31f3d054-0e2e-40eb-8a05-6f72dd122cf4/40695900507.pdf
- https://s3.amazonaws.com/mijedusovineti/reasoning_analogy_questions.pdf
- https://s3.amazonaws.com/fasanag/16061234457.pdf
- https://s3.amazonaws.com/tezofuretejom/3250963124.pdf
- https://s3.amazonaws.com/lijulijowivaze/homogeneous_and_heterogeneous_mixture_worksheet.pdf
- https://s3.amazonaws.com/felasorarabipis/82355586355.pdf
- https://cdn.shopify.com/s/files/1/0431/2658/7549/files/28534059491.pdf
- https://cdn.shopify.com/s/files/1/0483/6324/1632/files/kusudovufemokuvuxigabore.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report