SUSPICIOUS — joxiret.pdf
SUSPICIOUS — joxiret.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
fbfe4cb278e94644a0dae2214af15c5dd0cdf04f79c8102c6f9290b1f4d05058 - SHA-1:
dd78f51c442a849e733bee70e2eb4116104edca8 - MD5:
2677e42946bc25bd731131c5c7b96a25 - ssdeep:
768:1hgGzpDnSSHERG9vdu9LIvB4NbmIIVQG030awYfXubXNanZ+9EdqxO7qT4eqRhVl:EGF7SFRGNALQTQGFb9aZ+aq8eqRhVLx - TLSH:
T10E329EF35127DD8CBA85EF0359AA305C618ACB4831729AA459C97B7CC8B837D6E44E10 - Submitted as: joxiret.pdf
- File type: pdf · Size: 45406 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=farming+simulator+2012+android+apk+download, https://uploads.strikinglycdn.com/files/11889e3d-b0c0-4f1f-ba3e-7a38dbcc0d7e/88197642517.pdf, https://uploads.strikinglycdn.com/files/d18d4345-8191-4f31-9442-193a6f0413ed/nenikizuluzal.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=farming+simulator+2012+android+apk+download
- https://uploads.strikinglycdn.com/files/11889e3d-b0c0-4f1f-ba3e-7a38dbcc0d7e/88197642517.pdf
- https://uploads.strikinglycdn.com/files/d18d4345-8191-4f31-9442-193a6f0413ed/nenikizuluzal.pdf
- https://uploads.strikinglycdn.com/files/7b24bfdc-7d42-4fec-8e45-3d4f25f9e80d/foledubu.pdf
- https://uploads.strikinglycdn.com/files/c57f943c-b534-46f3-8a90-f9615e25e440/7485494832.pdf
- https://site-1038715.mozfiles.com/files/1038715/vifejakazemalolabuxume.pdf
- https://uploads.strikinglycdn.com/files/e699b47f-5a14-4fde-a754-a17d739a8890/63993502231.pdf
- https://uploads.strikinglycdn.com/files/42472eaf-237b-406d-844d-2505f1cd1e66/gepofuliwegawi.pdf
- https://cdn.shopify.com/s/files/1/0484/1711/2222/files/79809098164.pdf
- https://cdn.shopify.com/s/files/1/0429/2499/8819/files/bally_health_club.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1038715.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report