SUSPICIOUS — jemalonobusajiba.pdf
SUSPICIOUS — jemalonobusajiba.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
fa262e96bc66cdedb5fc9a19f9c8d461a9868c64e709f4f4dcb5b53ad98e6a64 - SHA-1:
9d9e353038e7b51c6be396d784f3290ee2d681f0 - MD5:
3ff34eaa4d304d67776d340f41162ec3 - ssdeep:
768:ZgGzpD6K25gnQ01AzwVXi05gF6YQW72CHWmBkB06QWQJn:aGF+ZgZCgXlgCo2CHWmBkRNQJn - TLSH:
T1CE329FF35167DC8C7B8AAB036DB7106C6146C78D31629AA058893B7CD0BC6FC7E50A61 - Submitted as: jemalonobusajiba.pdf
- File type: pdf · Size: 47085 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=surah+yasin+file+type+pdf, https://uploads.strikinglycdn.com/files/30db95e8-88f6-495c-864a-b3c18e5bcbb7/51129362398.pdf, https://uploads.strikinglycdn.com/files/30bf6e52-2a4d-47f4-bd05-c4bc45770201/34971957986.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=surah+yasin+file+type+pdf
- https://uploads.strikinglycdn.com/files/30db95e8-88f6-495c-864a-b3c18e5bcbb7/51129362398.pdf
- https://uploads.strikinglycdn.com/files/30bf6e52-2a4d-47f4-bd05-c4bc45770201/34971957986.pdf
- https://uploads.strikinglycdn.com/files/47456588-fbb4-40d9-ba91-7003003b4622/milubiseku.pdf
- https://uploads.strikinglycdn.com/files/694a754f-a56c-40b3-8516-40edfec265b4/47858492270.pdf
- https://site-1037835.mozfiles.com/files/1037835/29749669117.pdf
- https://site-1040144.mozfiles.com/files/1040144/91000173214.pdf
- https://site-1043032.mozfiles.com/files/1043032/64901941839.pdf
- https://site-1037075.mozfiles.com/files/1037075/93374151725.pdf
- https://site-1039420.mozfiles.com/files/1039420/99306848144.pdf
- https://site-1039311.mozfiles.com/files/1039311/33341265441.pdf
- https://site-1039427.mozfiles.com/files/1039427/79795868497.pdf
- https://site-1036699.mozfiles.com/files/1036699/39397121083.pdf
- https://site-1048190.mozfiles.com/files/1048190/54036894850.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1037835.mozfiles.com
- site-1040144.mozfiles.com
- site-1043032.mozfiles.com
- site-1037075.mozfiles.com
- site-1039420.mozfiles.com
- site-1039311.mozfiles.com
- site-1039427.mozfiles.com
- site-1036699.mozfiles.com
- site-1048190.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report