SUSPICIOUS — jobojuraserepaxa.pdf
SUSPICIOUS — jobojuraserepaxa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b06132713d46f9944f96a436cb2ce6a1c1984f89663b9c02150a9376b4efd363 - SHA-1:
76c3905643c46ee826df9628fb22348f25e11b67 - MD5:
68f5ac1d7974e4ee3f77d476c9d7df67 - ssdeep:
1536:LGF9epA78jU+e8nYO12mp/2tbPVaDchykZXrEvN7t78F50eDK9T:qF9eWG7YOQfbtacyktrQNBW50Z - TLSH:
T14636BFF35097EC8D6B8F9B435DF6416A2487C788712296A10899771ED4BC2BDBF00E60 - Submitted as: jobojuraserepaxa.pdf
- File type: pdf · Size: 68214 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=valores%20y%20etica%20ambiental, https://cdn.shopify.com/s/files/1/0433/4351/1706/files/wabagaweje.pdf, https://cdn.shopify.com/s/files/1/0483/8106/7421/files/comparing_rates_of_evaporation_lab_answers.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=valores%20y%20etica%20ambiental
- https://cdn.shopify.com/s/files/1/0433/4351/1706/files/wabagaweje.pdf
- https://cdn.shopify.com/s/files/1/0483/8106/7421/files/comparing_rates_of_evaporation_lab_answers.pdf
- https://cdn.shopify.com/s/files/1/0492/0134/8774/files/10013566669.pdf
- https://site-1038670.mozfiles.com/files/1038670/67379988576.pdf
- https://site-1036946.mozfiles.com/files/1036946/39234629453.pdf
- https://site-1036873.mozfiles.com/files/1036873/vidijoboxopofid.pdf
- https://cdn.shopify.com/s/files/1/0497/3491/0101/files/donkey_kong_rom_mame.pdf
- https://cdn.shopify.com/s/files/1/0479/8306/7292/files/goethe_c1_wortschatz.pdf
- https://cdn.shopify.com/s/files/1/0495/5835/6120/files/estudio_panoramico_del_nuevo_testamento.pdf
- https://cdn.shopify.com/s/files/1/0437/2286/6837/files/2545732519.pdf
- https://cdn.shopify.com/s/files/1/0500/8523/2811/files/gigazasajolisoxodiwam.pdf
- https://uploads.strikinglycdn.com/files/0b8c4b2a-d6c3-40f4-88e0-3c3d9ab55839/fawoxe.pdf
- https://uploads.strikinglycdn.com/files/1fddd6f8-be30-4245-95e5-8aa9568bdf60/32233430762.pdf
- https://uploads.strikinglycdn.com/files/cfb7fcea-1879-4ded-8b83-5f40fac17a8e/femiminiwevozerajirulipim.pdf
- https://uploads.strikinglycdn.com/files/b84ab4a8-04bb-4aac-b12a-692baffb0232/fiwukejasafabesar.pdf
- https://uploads.strikinglycdn.com/files/cb8d2c9f-1226-4067-8b20-260fa767c123/fugegixigokagode.pdf
- https://uploads.strikinglycdn.com/files/dc4e90cf-e782-4b0a-ad3f-64d29c25b930/48078368565.pdf
- https://uploads.strikinglycdn.com/files/b0b18295-7e6c-4ee7-b1ff-4c75bda7f2e3/fitevid.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f878dd8c3674.pdf
- https://cdn-cms.f-static.net/uploads/4368230/normal_5f87b716f3e93.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1038670.mozfiles.com
- site-1036946.mozfiles.com
- site-1036873.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report