SUSPICIOUS — texagovojedizaj.pdf
SUSPICIOUS — texagovojedizaj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f875ad9b370e50b0cffd510e6b8f7f2c740bc6287ef366977aedff221069ec33 - SHA-1:
d3e4ba8b4bc2e25f04d36697ac93e45d32d75847 - MD5:
2bc234ab5df34029697e13223df75cc4 - ssdeep:
768:N6gGzpDceQ3NFrEajrymxa6CDZYGXeFsGGuXq95f2ngz7bEPsX0ja5pkWZy+phNb:NnGFoeQEavyQa6hGXeeGFqDfBz7bEPaN - TLSH:
T13B338DF70493DC8C7BCBAF47A9FB10AA518AD3486036DBA01188676DC4BC6BD7E50950 - Submitted as: texagovojedizaj.pdf
- File type: pdf · Size: 48226 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=pre%20kindergarten%20reading%20worksheets, https://uploads.strikinglycdn.com/files/9407779e-23b0-4a90-a9d7-8f1e07ec1fc0/zaxaza.pdf, https://uploads.strikinglycdn.com/files/cef352d2-d7a8-4f09-9d8d-21f212c85d7f/jumifafutulu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=pre%20kindergarten%20reading%20worksheets
- https://uploads.strikinglycdn.com/files/9407779e-23b0-4a90-a9d7-8f1e07ec1fc0/zaxaza.pdf
- https://uploads.strikinglycdn.com/files/cef352d2-d7a8-4f09-9d8d-21f212c85d7f/jumifafutulu.pdf
- https://uploads.strikinglycdn.com/files/8faf5196-8778-4079-8099-eb835d092d90/supaxupukanono.pdf
- https://uploads.strikinglycdn.com/files/899fc9d4-0bd4-4918-80a9-26feafc9b819/kobuwonosuwijubugavub.pdf
- https://uploads.strikinglycdn.com/files/82f4e1b1-ed18-4b71-9f12-4420b28f1a3a/vafunaruvewapoduxipe.pdf
- https://site-1038322.mozfiles.com/files/1038322/pubazagaxemabof.pdf
- https://site-1038756.mozfiles.com/files/1038756/tireoidite_de_hashimoto.pdf
- https://site-1038553.mozfiles.com/files/1038553/saverezilizakaxivanab.pdf
- https://pidofuvu.weebly.com/uploads/1/3/0/7/130739764/lesabixejejafe.pdf
- https://kenilajapa.weebly.com/uploads/1/3/1/0/131069910/lojowuzesewat_tuxabikugu_wepapemefik_vizepibodu.pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/pazebazew.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/bdfa22f.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/vaxukekiwurefebe.pdf
- https://cdn.shopify.com/s/files/1/0266/7613/4082/files/vpn_free_betternet_hotspot_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0476/7996/3302/files/10927530111.pdf
- https://cdn.shopify.com/s/files/1/0438/6373/6485/files/3510908223.pdf
- https://cdn.shopify.com/s/files/1/0440/4133/9030/files/boom_blox_bash_party_wii_download.pdf
- https://uploads.strikinglycdn.com/files/61b1654f-9c80-4865-82b6-3ac4e88d3803/61614606560.pdf
- https://uploads.strikinglycdn.com/files/05564e4c-731a-4e50-bb33-e08a3123d943/81730452575.pdf
- https://uploads.strikinglycdn.com/files/7cc2d92d-9e45-45ee-bec0-5c5461f53b8c/85998466620.pdf
- https://uploads.strikinglycdn.com/files/40678bfd-2e0f-4327-a9a8-e323ba672a77/rusivilidubedip.pdf
- https://uploads.strikinglycdn.com/files/ac6c0a7e-526a-4600-8829-bcb170527d3c/61367589700.pdf
- https://uploads.strikinglycdn.com/files/5cb547f1-1239-4c18-a0e4-3b92bb33a7d0/jetomiferogujol.pdf
- https://uploads.strikinglycdn.com/files/895bcd16-7ed5-4f6b-92a0-8711c68798ef/16338002996.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1038322.mozfiles.com
- site-1038756.mozfiles.com
- site-1038553.mozfiles.com
- pidofuvu.weebly.com
- kenilajapa.weebly.com
- vekejuritikoj.weebly.com
- jaserasozupog.weebly.com
- keniwuki.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report