SUSPICIOUS — jetugapop.pdf
SUSPICIOUS — jetugapop.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f133d27155a693633d4b94fca06cb93cf7ed75ccd9b1dd4f7ed1a7aee0ca1b6f - SHA-1:
e3419d36a8527384b42ede190a0c0bc8904c7084 - MD5:
928f3bde90ac8c98c8ce48ce2d267467 - ssdeep:
1536:oPGFNeKSUvsCEKSlMstl6xllu+Wz1CD6HlPkhtgs:o+FNeKSUvNEKSlMst8kTM6W/ - TLSH:
T12E34BFF3159BED8DBA86DB0368B62458104AD74D623197E0858C7B2CC4BC6BDBF10E61 - Submitted as: jetugapop.pdf
- File type: pdf · Size: 56995 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ethiopian%20calendar%20download, https://uploads.strikinglycdn.com/files/9606bc28-91a4-4272-8859-0c00720ee999/jivowelenez.pdf, https://uploads.strikinglycdn.com/files/eb4c9b41-c4ba-41dc-9e8b-b141c3f30bdb/pasepali.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ethiopian%20calendar%20download
- https://uploads.strikinglycdn.com/files/9606bc28-91a4-4272-8859-0c00720ee999/jivowelenez.pdf
- https://uploads.strikinglycdn.com/files/eb4c9b41-c4ba-41dc-9e8b-b141c3f30bdb/pasepali.pdf
- https://uploads.strikinglycdn.com/files/8a028c24-137a-4326-88f6-377526456a8a/tewepus.pdf
- https://uploads.strikinglycdn.com/files/0860a254-75b7-4884-b3ce-9dbf52a68521/48358771071.pdf
- https://uploads.strikinglycdn.com/files/d8d07d46-1d35-4bb9-a792-32054809ece0/44428995085.pdf
- https://site-1038412.mozfiles.com/files/1038412/76986617929.pdf
- https://site-1039970.mozfiles.com/files/1039970/13387865437.pdf
- https://site-1043479.mozfiles.com/files/1043479/56425829175.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f875b6a6a5e7.pdf
- https://cdn-cms.f-static.net/uploads/4367668/normal_5f8752036c545.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f870636ee6eb.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f8751a8501e2.pdf
- https://cdn.shopify.com/s/files/1/0499/5963/3064/files/jutoduwasenupenegazob.pdf
- https://cdn.shopify.com/s/files/1/0432/9213/1484/files/microsoft_access_2003_tutorial_for_beginners.pdf
- https://cdn.shopify.com/s/files/1/0460/2131/2671/files/practice_5-2_solving_percent_problems_using_proportions_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0502/0306/6551/files/digitech_jamman_stereo_looper_phrase_sampler_manual.pdf
- https://cdn.shopify.com/s/files/1/0485/9641/8720/files/25227785510.pdf
- https://uploads.strikinglycdn.com/files/4911b968-13ca-4f52-927e-927803a1c369/24306404877.pdf
- https://uploads.strikinglycdn.com/files/79035d2f-87b9-4c4d-b487-ee0205fcd3e5/ragudizisikewafezo.pdf
- https://uploads.strikinglycdn.com/files/6c67aca4-a035-4548-a4be-d85b18a05f5e/bazisejaledixabof.pdf
- https://uploads.strikinglycdn.com/files/f434198a-7036-44de-bf69-66a580c20804/vodozo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1038412.mozfiles.com
- site-1039970.mozfiles.com
- site-1043479.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report