SUSPICIOUS — jufotavegotodun_doteluve_fuvij.pdf
SUSPICIOUS — jufotavegotodun_doteluve_fuvij.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e495b1bd3ba1affa5b2492d6c4be21c5787a1ae269f1e5597f9115db2cadd3df - SHA-1:
54954d57af88e0e82ff88fb8f34fe487fe190c27 - MD5:
9e6cbaf5083f74b071cfe0155e18a55d - ssdeep:
1536:+GFkp9xueCenc0PpTnVmvYIbAAoY/qW5IWGc1We4eX:nFkpFncapZmvXkAN/vIWrWC - TLSH:
T1AC36BFF711A7ED8D6EC7AF43ADA70168608ED6886133E79040CC6B2CD47C6ED6E10A51 - Submitted as: jufotavegotodun_doteluve_fuvij.pdf
- File type: pdf · Size: 64489 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=kamstrup%20multical%20602%20modbus%20datasheet, https://uploads.strikinglycdn.com/files/9111f8e9-2005-423d-bc91-48cd6e0acffb/64782046750.pdf, https://uploads.strikinglycdn.com/files/43735518-5ce6-4bde-9b5b-c2a1e2479243/58351315807.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=kamstrup%20multical%20602%20modbus%20datasheet
- https://uploads.strikinglycdn.com/files/9111f8e9-2005-423d-bc91-48cd6e0acffb/64782046750.pdf
- https://uploads.strikinglycdn.com/files/43735518-5ce6-4bde-9b5b-c2a1e2479243/58351315807.pdf
- https://uploads.strikinglycdn.com/files/75a445d3-78bb-4989-919b-9a6bf8b102b8/lulijixu.pdf
- https://uploads.strikinglycdn.com/files/475bb819-fa98-44ca-8a0c-5b23963099d4/fetewufogupapozoxeza.pdf
- https://cdn.shopify.com/s/files/1/0498/8734/6846/files/bofalokijegonedomegupi.pdf
- https://cdn.shopify.com/s/files/1/0484/1331/1133/files/jorer.pdf
- https://cdn.shopify.com/s/files/1/0497/1462/6717/files/drow_ranger_build_guide_dota_1.pdf
- https://cdn-cms.f-static.net/uploads/4367290/normal_5f89738812835.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f8744b85f3b3.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f89280c09ea7.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f87103e24940.pdf
- https://cdn.shopify.com/s/files/1/0428/8249/8716/files/noligipokesibozokutaded.pdf
- https://cdn.shopify.com/s/files/1/0499/6543/3000/files/xopavinilovufibureda.pdf
- https://cdn.shopify.com/s/files/1/0482/7221/2132/files/30406827575.pdf
- https://cdn.shopify.com/s/files/1/0481/6224/2727/files/bexexukolafen.pdf
- https://cdn.shopify.com/s/files/1/0501/7426/3456/files/lifetime_storage_box_116_gallon.pdf
- https://uploads.strikinglycdn.com/files/cfb24dd8-cc77-4ee3-971b-35a05c8f6441/9231488872.pdf
- https://uploads.strikinglycdn.com/files/9cd2d0a7-9496-4ba6-8e06-2c6fa3c014ea/palit.pdf
- https://uploads.strikinglycdn.com/files/6e33e402-bbc9-4317-afc4-52120775d347/romadefawowitapamarakib.pdf
- https://uploads.strikinglycdn.com/files/2ae6a526-c137-4a11-b1dc-ba2c0aed1f93/37343775916.pdf
- https://uploads.strikinglycdn.com/files/d33841bc-d233-4103-8989-a80400080acf/23327074345.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report