SUSPICIOUS — jububij-fuvozuzav.pdf
SUSPICIOUS — jububij-fuvozuzav.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
cb1b3628a909d1706720704a53d954f534c3629cad6b32321695db305b67d4a3 - SHA-1:
8eb3dd321754760ccbdf387af45b8697c2dbbd76 - MD5:
e6921f11f8210e3bfaf38308c6bc435b - ssdeep:
768:KgGzpDRp8yKhqnFM5bwqfRz9rjdZB7iHDZ3LQiil4yPre33MX6orT7U9w97+LxY:XGFtpIdZB7w1bQia42wVoDU9TLxY - TLSH:
T13D339EF710A7EC8D7A8B6F43ADAB11AA9089C74C6137EB90589C737CC16C1AD3E50851 - Submitted as: jububij-fuvozuzav.pdf
- File type: pdf · Size: 50318 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=the%20adventures%20of%20tom%20bombadil, https://cdn.shopify.com/s/files/1/0432/5025/3984/files/20657521331.pdf, https://cdn.shopify.com/s/files/1/0436/9491/5738/files/87172915184.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=the%20adventures%20of%20tom%20bombadil
- https://cdn.shopify.com/s/files/1/0432/5025/3984/files/20657521331.pdf
- https://cdn.shopify.com/s/files/1/0436/9491/5738/files/87172915184.pdf
- https://cdn.shopify.com/s/files/1/0499/9089/3730/files/87090952764.pdf
- https://cdn.shopify.com/s/files/1/0499/9377/7302/files/how_do_you_calculate_total_fixed_costs.pdf
- https://cdn.shopify.com/s/files/1/0431/5778/2694/files/47305161258.pdf
- https://cdn.shopify.com/s/files/1/0500/5764/2152/files/sit_and_stand_double_stroller_accessories.pdf
- https://cdn.shopify.com/s/files/1/0480/9103/7859/files/skyrim_better_faces_mod.pdf
- https://cdn.shopify.com/s/files/1/0495/9204/1624/files/how_to_remove_gum_stains_from_glass.pdf
- https://s3.amazonaws.com/sugaguxagu/ansible_tutorial.pdf
- https://s3.amazonaws.com/zetare/70517880191.pdf
- https://s3.amazonaws.com/sugaguxagu/98377364643.pdf
- https://vaxajiwozoli.weebly.com/uploads/1/3/1/6/131637631/liwuzi-jinojubuxadiz-jekejixakufasus-bidowapojubozel.pdf
- https://kenilajapa.weebly.com/uploads/1/3/1/0/131069910/4925866.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/2108399.pdf
- https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/1285448.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/xududev-ledavodu-jatulivarolaxe-bixebenal.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86f91353c9e.pdf
- https://cdn-cms.f-static.net/uploads/4379726/normal_5f8eb8b5d9cfc.pdf
- https://cdn-cms.f-static.net/uploads/4383703/normal_5f8d7537f250f.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f86fea543283.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f874ae48967b.pdf
- https://uploads.strikinglycdn.com/files/a88db1bf-3e26-4a83-b4e1-764f9536c6c6/judofewanumikuzozavu.pdf
- https://uploads.strikinglycdn.com/files/96af1d01-8e79-4b3b-9759-986bd537b32e/betep.pdf
- https://uploads.strikinglycdn.com/files/3dea54da-55aa-42ea-8ad4-7e668a0ff547/kovufexaxipu.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- vaxajiwozoli.weebly.com
- kenilajapa.weebly.com
- mupibidegupek.weebly.com
- saxexowiki.weebly.com
- jakedekokobara.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report