SUSPICIOUS — bofagekibexo.pdf
SUSPICIOUS — bofagekibexo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3b98198c8fa047e1d5fb36e0b14079f76f58de6f2e69b7049bccf77d13e7bbf7 - SHA-1:
299277f10366c1570cefec8f584a1df58583d76e - MD5:
5cc25cbe99a3a3ecb50478f94bb6b4fb - ssdeep:
768:ggGzpDrX4jBWub0xbYpL+znMXlVlp5uB7iOrHEy5wjH:tGFvX40sK+A93ky5wjH - TLSH:
T11E306CF30067EE8CBA8B9B476EA701996046C38D70369760149CB76CD57C6EEBF00A51 - Submitted as: bofagekibexo.pdf
- File type: pdf · Size: 38146 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=caballo+de+troya+9+pdf+espa%25C3%25B1ol, https://site-1036689.mozfiles.com/files/1036689/falisenovedodovodibi.pdf, https://site-1037082.mozfiles.com/files/1037082/xajekew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=caballo+de+troya+9+pdf+espa%25C3%25B1ol
- https://site-1036689.mozfiles.com/files/1036689/falisenovedodovodibi.pdf
- https://site-1037082.mozfiles.com/files/1037082/xajekew.pdf
- https://site-1036743.mozfiles.com/files/1036743/74617211050.pdf
- https://site-1036685.mozfiles.com/files/1036685/39093684350.pdf
- https://site-1036655.mozfiles.com/files/1036655/zawagawipoxelibofow.pdf
- https://site-1036951.mozfiles.com/files/1036951/nevanokixivilad.pdf
- https://site-1037207.mozfiles.com/files/1037207/judid.pdf
- https://site-1036816.mozfiles.com/files/1036816/57514315851.pdf
- https://site-1036930.mozfiles.com/files/1036930/danozevoxunosurivufa.pdf
- https://uploads.strikinglycdn.com/files/bda47c45-3ae4-49cc-8e5c-03832d661573/pukerutadut.pdf
- https://uploads.strikinglycdn.com/files/9ac857d6-521c-4ceb-8b34-8b98829c9097/37235045897.pdf
- https://uploads.strikinglycdn.com/files/d5211bd7-f218-4e35-96d6-fa5b72648e91/21505342525.pdf
- https://uploads.strikinglycdn.com/files/1821f08d-043e-45c1-8270-6534d5930c8f/difiketo.pdf
- https://uploads.strikinglycdn.com/files/1a7873e8-228d-410e-bd92-fcaaecd0a76c/dapetowexamefisovelud.pdf
- https://cdn.shopify.com/s/files/1/0433/3672/8744/files/7301041983.pdf
- https://cdn.shopify.com/s/files/1/0432/2210/6271/files/vufuxitadedemewenopazivil.pdf
- https://cdn.shopify.com/s/files/1/0430/9729/2967/files/42542530935.pdf
- https://cdn.shopify.com/s/files/1/0486/2862/9669/files/74560566176.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036689.mozfiles.com
- site-1037082.mozfiles.com
- site-1036743.mozfiles.com
- site-1036685.mozfiles.com
- site-1036655.mozfiles.com
- site-1036951.mozfiles.com
- site-1037207.mozfiles.com
- site-1036816.mozfiles.com
- site-1036930.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report