SUSPICIOUS — jepow_kesebed_rigemuxunuv.pdf
SUSPICIOUS — jepow_kesebed_rigemuxunuv.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e901de2c1842c864d5fd91eaedb2f7393262baeff2f7136f968532a123ab741c - SHA-1:
f9404397be7cbafb36d7128958425cb61075015e - MD5:
9f9b87412204d0af7aaf0c3db4fe8eb9 - ssdeep:
768:TgGzpDAp7tl/eoiVFkb+MHJW70mmhoaO6qFW0IE4Xh14a83z6lAF2MMvAoxcZ:sGFUphJA0mdYCIE4Xh14dfZM4oxcZ - TLSH:
T10D328DF34093EC8C7ACFAB43AEA71599904AD788912AD360549C7B2DC07CAFC6F10951 - Submitted as: jepow_kesebed_rigemuxunuv.pdf
- File type: pdf · Size: 44225 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=baby%20brezza%20sterilizer%20dryer%20manual, https://cdn-cms.f-static.net/uploads/4368222/normal_5f88170524f24.pdf, https://cdn-cms.f-static.net/uploads/4368503/normal_5f87835e46fd1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=baby%20brezza%20sterilizer%20dryer%20manual
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f88170524f24.pdf
- https://cdn-cms.f-static.net/uploads/4368503/normal_5f87835e46fd1.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f87c4f6ebf96.pdf
- https://cdn-cms.f-static.net/uploads/4368985/normal_5f87dc2729d60.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f873bbf2ef5e.pdf
- https://cdn.shopify.com/s/files/1/0483/0540/6115/files/javidijejoridovobojakubub.pdf
- https://site-1038310.mozfiles.com/files/1038310/42644908766.pdf
- https://site-1036791.mozfiles.com/files/1036791/xixupiv.pdf
- https://site-1039834.mozfiles.com/files/1039834/ground_water_recharging.pdf
- https://site-1040320.mozfiles.com/files/1040320/40845665350.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f871bca777e1.pdf
- https://cdn-cms.f-static.net/uploads/4366351/normal_5f87361389ccc.pdf
- https://cdn-cms.f-static.net/uploads/4366989/normal_5f872aa88f5f0.pdf
- https://uploads.strikinglycdn.com/files/899c00fb-9770-453d-8b00-db2347ebe238/wanewipokesiburaraxiwabit.pdf
- https://uploads.strikinglycdn.com/files/f62c40f0-2f93-4f73-aa3e-879a9a3615ae/bedubagesabaxoxavij.pdf
- https://uploads.strikinglycdn.com/files/ba9f1ca9-2c84-468f-9cd1-3edf8d2c7f81/2965432316.pdf
- https://uploads.strikinglycdn.com/files/947bebe7-b954-4d39-963a-cba5eb41b0fa/nezuwatasuru.pdf
- https://uploads.strikinglycdn.com/files/c32622b7-dff3-4eff-9064-3296ad392431/xatisu.pdf
- https://uploads.strikinglycdn.com/files/a2f3e38e-bdf5-47d4-b7d9-9a358824d2ba/48849337969.pdf
- https://uploads.strikinglycdn.com/files/fc89cce9-610c-491d-ba12-412ce1adc3ba/suriwononox.pdf
- https://uploads.strikinglycdn.com/files/00255866-8294-4cfb-842f-ad39e5cb6ebc/puwutumedawasomaremedi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1038310.mozfiles.com
- site-1036791.mozfiles.com
- site-1039834.mozfiles.com
- site-1040320.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report