SUSPICIOUS — gajadilumar-nunojezeku-jogiwer.pdf
SUSPICIOUS — gajadilumar-nunojezeku-jogiwer.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
befacca81a8128f36ee7aef527ee694e94e19a6cd07dcc9de41d3baa67ebe3a8 - SHA-1:
0967620689db3810bcbb4438cda175dae6f754f9 - MD5:
7546a2777dfda97545e43824cdb3d923 - ssdeep:
768:UgGzpDRx+obecOr1dl9D1sR4Ji7q8WHwMfH1i4iMgW0oPIFErZQKPzq+l/jtE:hGFtCc7HGHdiSBPCEPPzqE/jtE - TLSH:
T13E33BEF3509BED4C7A866B43AE6A102D654EC7886133B75454C87B2DC8BC1EC3E44861 - Submitted as: gajadilumar-nunojezeku-jogiwer.pdf
- File type: pdf · Size: 50074 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=a%20novel%20without%20a%20name%20summary, https://cdn-cms.f-static.net/uploads/4367938/normal_5f88aa79e8aa0.pdf, https://cdn.shopify.com/s/files/1/0437/3607/2341/files/47792297551.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=a%20novel%20without%20a%20name%20summary
- https://cdn-cms.f-static.net/uploads/4367938/normal_5f88aa79e8aa0.pdf
- https://cdn.shopify.com/s/files/1/0437/3607/2341/files/47792297551.pdf
- https://uploads.strikinglycdn.com/files/0a76cee9-6cc0-4fce-a52b-7841703431c4/zujixoxujomifokotaxikiw.pdf
- https://uploads.strikinglycdn.com/files/97a8d45c-bff3-4901-ac82-602195b96ada/75344445841.pdf
- https://cdn.shopify.com/s/files/1/0268/7811/6027/files/puruvewureboxamuso.pdf
- https://cdn.shopify.com/s/files/1/0500/4787/7284/files/avancemos_unit_2_lesson_1_answers.pdf
- https://cdn-cms.f-static.net/uploads/4386834/normal_5f91b2f2b3953.pdf
- https://cdn.shopify.com/s/files/1/0500/1058/7296/files/raised_vegetable_garden_planting_guide.pdf
- https://uploads.strikinglycdn.com/files/34e25d54-39b3-4959-9203-5f98ac22edcd/kifivibesulasakomilifemo.pdf
- https://cdn-cms.f-static.net/uploads/4403820/normal_5f970150be5ea.pdf
- https://cdn-cms.f-static.net/uploads/4403556/normal_5f9e89c44c0bc.pdf
- https://cdn-cms.f-static.net/uploads/4385852/normal_5f953dbf0a9c8.pdf
- https://uploads.strikinglycdn.com/files/e43deb38-a6fa-4598-a521-2213dd88305a/jusiboliz.pdf
- https://cdn.shopify.com/s/files/1/0507/5389/6623/files/tusisowopusijakutoviru.pdf
- https://cdn-cms.f-static.net/uploads/4383794/normal_5f8e4ac9d57f3.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f9a45abe51d5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report