SUSPICIOUS — dejifijatod.pdf
SUSPICIOUS — dejifijatod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e8dc074b6bf1d7a52513fafd934589a8c9889143e7ed05d4214bb2d9c77b395e - SHA-1:
c8e9f9e3ca48f432f3fe34ab0aff4f0df2d70b1c - MD5:
3072e0d37932cb3408151490b75f1f8f - ssdeep:
768:tgGzpDipyws7LXPrIIGJJMC/V6zehsnuFSkXoUh8Hr/9erX:OGFepUeGnwSMC9erX - TLSH:
T196306CF31097ED4C7A8E6F03ADAB115D6189D38D7132E7A005883A6CD47CAEC7E00A61 - Submitted as: dejifijatod.pdf
- File type: pdf · Size: 37220 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=fraction%20word%20problems%20year%203%20pdf, https://cdn-cms.f-static.net/uploads/4368468/normal_5f8853074eccf.pdf, https://cdn-cms.f-static.net/uploads/4366625/normal_5f875df05a6d6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=fraction%20word%20problems%20year%203%20pdf
- https://cdn-cms.f-static.net/uploads/4368468/normal_5f8853074eccf.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f875df05a6d6.pdf
- https://cdn-cms.f-static.net/uploads/4388052/normal_5f8d10c4da1ad.pdf
- https://cdn-cms.f-static.net/uploads/4368978/normal_5f88b778baca3.pdf
- https://cdn.shopify.com/s/files/1/0497/5362/0634/files/69508012489.pdf
- https://cdn.shopify.com/s/files/1/0481/5916/2521/files/cancer_de_tiroides_anaplasico.pdf
- https://cdn.shopify.com/s/files/1/0435/6875/8943/files/71851558026.pdf
- https://cdn.shopify.com/s/files/1/0440/5949/2517/files/old_hymn_white_as_snow.pdf
- https://cdn.shopify.com/s/files/1/0502/9770/0549/files/tool__die_maker_books.pdf
- https://cdn.shopify.com/s/files/1/0428/9147/7159/files/sibalujeb.pdf
- https://cdn.shopify.com/s/files/1/0482/5042/1410/files/76165202344.pdf
- https://cdn.shopify.com/s/files/1/0482/2895/8365/files/tuzomabogojaxifix.pdf
- https://cdn-cms.f-static.net/uploads/4370066/normal_5f8942f86e1de.pdf
- https://cdn-cms.f-static.net/uploads/4391634/normal_5f92108b06c13.pdf
- https://cdn-cms.f-static.net/uploads/4368951/normal_5f8b6609882a5.pdf
- https://migirebunimalab.weebly.com/uploads/1/3/1/3/131383914/8ca0bf3d.pdf
- https://sujajikozodes.weebly.com/uploads/1/3/1/3/131384638/1161639.pdf
- https://s3.amazonaws.com/susopuzupure/98883979220.pdf
- https://s3.amazonaws.com/wilugugo/beethoven_piano_sonata_23.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- migirebunimalab.weebly.com
- sujajikozodes.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report