SUSPICIOUS — gaxagijokudimekoj.pdf
SUSPICIOUS — gaxagijokudimekoj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2fad44c4fca61ff6871bde866a2f5623f1f94beb133cf409b9bd75a3346d4f7a - SHA-1:
a05a0c4ed4144e3f494ca80261233c55deb00172 - MD5:
f6cfdb24dc34900829b1e7668b16c0de - ssdeep:
768:8HgGzpD8eL7k2cQfZ6vW6e7tkUKoh2eNiikWZBiPoPxJ9yEvQmPMg//Fh5AjtLvi:5GFYe1tkUKoh2eNiikWZBiP2BQIMgHmq - TLSH:
T1A6339EF350ABDC9D6A86AB43A9A610296159D3887332D7B444CC777CC47C7BE6F10A20 - Submitted as: gaxagijokudimekoj.pdf
- File type: pdf · Size: 47862 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=three+idiots+english+sub, https://cdn.shopify.com/s/files/1/0497/5152/3482/files/san_marcos_creek_specific_plan.pdf, https://cdn.shopify.com/s/files/1/0484/4784/8602/files/35116198112.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=three+idiots+english+sub
- https://cdn.shopify.com/s/files/1/0497/5152/3482/files/san_marcos_creek_specific_plan.pdf
- https://cdn.shopify.com/s/files/1/0484/4784/8602/files/35116198112.pdf
- https://cdn.shopify.com/s/files/1/0429/1582/3772/files/tofotokoridawuregim.pdf
- https://cdn.shopify.com/s/files/1/0437/9816/7709/files/22659450608.pdf
- https://cdn.shopify.com/s/files/1/0435/1534/7103/files/provo_utah_full_zip_code.pdf
- http://files.noltextruss.com/uploads/1/3/1/4/131406036/kukogos-bejinijebewuni-berudiliro.pdf
- https://uploads.strikinglycdn.com/files/08acb4cf-3810-49da-9f72-d9bfe7817fac/legunawaga.pdf
- https://uploads.strikinglycdn.com/files/f80c4bdc-f93c-4ed8-acd4-52ab76be3da9/xugobodelofigijotiloxasa.pdf
- https://uploads.strikinglycdn.com/files/061706fe-0d4d-4bdc-9954-8a74f7ef392d/nenupidafivekudi.pdf
- https://uploads.strikinglycdn.com/files/a3f64c9f-6898-4cb2-b7a5-a553b382a964/95194105433.pdf
- https://uploads.strikinglycdn.com/files/81f9f876-4bda-4f10-9452-2581d6eec5ed/wibixogel.pdf
- https://uploads.strikinglycdn.com/files/91bebbab-33f8-4e63-9cd2-04c30b121ece/suvasuzokajowifugarobelu.pdf
- https://uploads.strikinglycdn.com/files/2e135c5d-65c6-44dd-9b22-c97c18250f92/vinezufixunaxulixosul.pdf
- https://uploads.strikinglycdn.com/files/38eb2dd5-cf2a-4c49-be09-87aa52286ff8/dogekonometer.pdf
- https://uploads.strikinglycdn.com/files/9cbfd241-638f-4161-ad65-6d763e166983/91594406494.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- files.noltextruss.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report