SUSPICIOUS — nejawijumijidoxilokapik.pdf
SUSPICIOUS — nejawijumijidoxilokapik.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
12a58633902f8761422b43252e87cb9102bea2f661420f175fb92622ca19744a - SHA-1:
2fc22a4c7ad17b41e3d31b4d0ba8c01751464a74 - MD5:
76a508e844cf4dd397d530daf2c17c2d - ssdeep:
768:JgGzpDFVMqKc3rxZxn1MezdjDIYc71SGSnCAd49MtK2lFN3k:qGF5pFnn12xSGYbd4atK2Hk - TLSH:
T183319DF710A7ED8CBA869B13ADA709695189D3487233EBA054CDB77CC47C6BD6D01820 - Submitted as: nejawijumijidoxilokapik.pdf
- File type: pdf · Size: 42887 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=mio+fratello+rincorre+i+dinosauri+pdf, http://files.washingtonbands.org/uploads/1/3/1/6/131606047/9528050.pdf, http://files.pacer-drama.org/uploads/1/3/0/8/130813777/57c22cdc90a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=mio+fratello+rincorre+i+dinosauri+pdf
- http://files.washingtonbands.org/uploads/1/3/1/6/131606047/9528050.pdf
- http://files.pacer-drama.org/uploads/1/3/0/8/130813777/57c22cdc90a.pdf
- http://vixanetut.kellytobias.com/uploads/1/3/0/7/130775634/2152970.pdf
- http://files.360visualhome.com/uploads/1/3/0/7/130740257/toxajiborupinesujad.pdf
- http://fawovosi.ourwildthings.co.uk/uploads/1/3/0/7/130776485/masesevasupunus.pdf
- http://files.smartdogswalk.com/uploads/1/3/0/7/130739621/3e4a1d23c5af3a8.pdf
- http://pitipe.sprykegame.com/uploads/1/3/0/7/130776366/9261350.pdf
- http://wojej.orpheusnorthherts.com/uploads/1/3/0/7/130738894/figonegejut-zugilon.pdf
- http://kimusukoz.audaciousdivas.org/uploads/1/3/2/6/132683209/tajowa.pdf
- http://files.apecs-bulgaria.com/uploads/1/3/1/1/131164012/24ce15.pdf
- http://files.lungtaworld.com/uploads/1/3/1/4/131452903/worawedo_fifazidodibugeb.pdf
- http://feveguwib.governmentinformationday.ca/uploads/1/3/0/7/130775310/tirogojezezapaw.pdf
- http://files.saintsugaroflondon.com/uploads/1/3/2/3/132302824/b79b0.pdf
- http://garin.abplasticpro.com/uploads/1/3/1/4/131482992/7046972.pdf
- http://files.bafwv.org/uploads/1/3/1/8/131871894/vojaguxik.pdf
- http://bojir.phoenixhomesuk.com/uploads/1/3/0/8/130873987/bezajokoror_galofig_kawud.pdf
- http://raborix.ethridgedesignstudio.com/uploads/1/3/1/3/131380213/jabepitifesarasabol.pdf
- http://files.bodylistener-hk.com/uploads/1/3/0/7/130739971/bonozerikabivab_funirugalu_dowaluzaro_wawamo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- files.washingtonbands.org
- files.pacer-drama.org
- vixanetut.kellytobias.com
- files.360visualhome.com
- fawovosi.ourwildthings.co.uk
- files.smartdogswalk.com
- pitipe.sprykegame.com
- wojej.orpheusnorthherts.com
- kimusukoz.audaciousdivas.org
- files.apecs-bulgaria.com
- files.lungtaworld.com
- feveguwib.governmentinformationday.ca
- files.saintsugaroflondon.com
- garin.abplasticpro.com
- files.bafwv.org
- bojir.phoenixhomesuk.com
- raborix.ethridgedesignstudio.com
- files.bodylistener-hk.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report