SUSPICIOUS — fevojoxapasulovabo.pdf
SUSPICIOUS — fevojoxapasulovabo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3b7ec52ada2dcbc0a122cec2a0407c71e6696e2b9da33a594ca6cf1246acf656 - SHA-1:
af36749ffa583cb03a23f8acc58ca550e9ecf5f5 - MD5:
69f4100698b1ebfeed0d3f49a323c70f - ssdeep:
768:9gGzpDoxyET3SaslzRZKXbYW4vXGQ21ypMe8gDZC5ET7uKPzYI4L+r:+GFkyzvXGQ21OR8SC5tKPzYI4L+r - TLSH:
T1AD329EF3149BEC4D7A8BAB03ADF3015AA045C7886277AB6045CC772CD47CAAD7E50861 - Submitted as: fevojoxapasulovabo.pdf
- File type: pdf · Size: 43632 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=ksu+general+education+requirements, https://cdn.shopify.com/s/files/1/0464/8553/6920/files/direct_square_variation_worksheet_with_answer_key.pdf, https://cdn.shopify.com/s/files/1/0486/4078/6600/files/finobagaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=ksu+general+education+requirements
- https://cdn.shopify.com/s/files/1/0464/8553/6920/files/direct_square_variation_worksheet_with_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0486/4078/6600/files/finobagaf.pdf
- https://cdn.shopify.com/s/files/1/0440/7099/4085/files/mutually_exclusive_inclusive_probability_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0435/7259/2801/files/bo2_cracked_pc.pdf
- https://cdn.shopify.com/s/files/1/0433/4885/2904/files/derrida_signature_event_context.pdf
- https://cdn.shopify.com/s/files/1/0478/4622/8127/files/89539565856.pdf
- https://cdn.shopify.com/s/files/1/0496/2726/7235/files/sipuz.pdf
- https://cdn.shopify.com/s/files/1/0441/3086/1208/files/69223852748.pdf
- https://cdn.shopify.com/s/files/1/0430/9401/6157/files/rifojug.pdf
- https://cdn.shopify.com/s/files/1/0429/3846/6471/files/13816134765.pdf
- http://files.motionxsynergy.com/uploads/1/3/0/8/130814172/878914.pdf
- http://kokulun.mychoice411.com/uploads/1/3/0/9/130969754/9dd05c1479e8.pdf
- http://files.troliosprint.net/uploads/1/3/1/6/131606373/21ff22fcc5b3c13.pdf
- http://wubotuv.kerikerischoolofmusic.org/uploads/1/3/1/1/131163635/wuzisa_xawosunafa.pdf
- http://nikuku.ladiesofcharitymemphis.org/uploads/1/3/0/9/130969744/jekor-zidujikix-lidejedozo.pdf
- http://files.davidjuliamusic.com/uploads/1/3/0/8/130813881/c718687f99b3b.pdf
- http://lapejam.greekhouserestaurant.ca/uploads/1/3/0/7/130739663/d05f7d4438757b.pdf
- http://padenet.multimediocrityshow.com/uploads/1/3/1/4/131437987/ratevevilafaxi-juwalefi-gezenolofasujub.pdf
- http://files.gcs-fsaa.com/uploads/1/3/1/8/131859993/baxetutegut_lagukone_difafir.pdf
- http://files.kisband.org/uploads/1/3/0/8/130814172/94c0022330b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- files.motionxsynergy.com
- kokulun.mychoice411.com
- files.troliosprint.net
- wubotuv.kerikerischoolofmusic.org
- nikuku.ladiesofcharitymemphis.org
- files.davidjuliamusic.com
- lapejam.greekhouserestaurant.ca
- padenet.multimediocrityshow.com
- files.gcs-fsaa.com
- files.kisband.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report