SUSPICIOUS — dogajufadenomun.pdf
SUSPICIOUS — dogajufadenomun.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
cfc4c1210d9cb070f510c30b09d7520a7bf41d8ce824d19c7db54014089ebebe - SHA-1:
5813dfc3b99b0f38e3dc13217e0441fbb0133bfd - MD5:
0c655a2c78f1dea7c3f830ea1d543821 - ssdeep:
768:9gGzpDQpWUFcw7nf0CISPkZ0BUsK2AqfZvrhhCM6an/4hezOfaork60FSDd4hyUS:+GFMpWCf0Cd+anYwOfaEkfFE4hynOmhB - TLSH:
T172338DF31097DD8D7B8B6B079DAB149D604AD389A1239790058C7B3CD4BCBAE2E01A51 - Submitted as: dogajufadenomun.pdf
- File type: pdf · Size: 47900 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=2020+volkswagen+jetta+2.0t+manual, https://cdn-cms.f-static.net/uploads/4369648/normal_5f88ba688fe01.pdf, https://cdn-cms.f-static.net/uploads/4372696/normal_5f88bac376490.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=2020+volkswagen+jetta+2.0t+manual
- https://cdn-cms.f-static.net/uploads/4369648/normal_5f88ba688fe01.pdf
- https://cdn-cms.f-static.net/uploads/4372696/normal_5f88bac376490.pdf
- https://cdn-cms.f-static.net/uploads/4369926/normal_5f88a3cc33393.pdf
- https://cdn-cms.f-static.net/uploads/4368474/normal_5f87f77f52096.pdf
- https://cdn.shopify.com/s/files/1/0502/0719/5311/files/72300137549.pdf
- https://cdn.shopify.com/s/files/1/0481/3042/4985/files/magellan_meridian_gold_gps_user_manual.pdf
- https://cdn.shopify.com/s/files/1/0483/4770/9591/files/93189200335.pdf
- https://cdn.shopify.com/s/files/1/0432/8492/2526/files/macx_dvd_ripper_pro_serial_number.pdf
- https://cdn.shopify.com/s/files/1/0497/1069/4557/files/zorejaxekalologisep.pdf
- https://uploads.strikinglycdn.com/files/f8155892-c23f-4e07-8e3b-509c593a73ea/sajuvi.pdf
- https://uploads.strikinglycdn.com/files/acbdf003-25a4-4c66-bd07-0dcb025914d6/bomumarujararopabefavar.pdf
- https://uploads.strikinglycdn.com/files/e674893a-c218-4422-a83b-6d9d21b08de4/40223924644.pdf
- https://uploads.strikinglycdn.com/files/868fab8f-9bf8-4760-a64d-e4af1047f72d/30415104096.pdf
- https://uploads.strikinglycdn.com/files/8391596b-127c-4fb7-8ac7-a32a641ebb8a/53236787453.pdf
- https://cdn.shopify.com/s/files/1/0433/3921/9099/files/a_fuller_explanation.pdf
- https://cdn.shopify.com/s/files/1/0500/4247/0550/files/manitowoc_public_school_district_address.pdf
- https://cdn.shopify.com/s/files/1/0437/6818/4994/files/make_chocolate_fair.pdf
- https://cdn.shopify.com/s/files/1/0486/1365/4696/files/taperizetilepawipivos.pdf
- https://cdn.shopify.com/s/files/1/0502/9963/3829/files/saxosowefo.pdf
- https://site-1040224.mozfiles.com/files/1040224/27793169077.pdf
- https://site-1043963.mozfiles.com/files/1043963/29638356591.pdf
- https://site-1038572.mozfiles.com/files/1038572/86724094459.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86fbecea432.pdf
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f88ba530e76d.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1040224.mozfiles.com
- site-1043963.mozfiles.com
- site-1038572.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report