SUSPICIOUS — gixisavusapijunerifetap.pdf
SUSPICIOUS — gixisavusapijunerifetap.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3ced227c87bc3542ba5084eb8f1d7e94ca6f814fdece7aef73778dfffe73dccc - SHA-1:
efb3c9a2e8533f28ee6aa2d76834b71432d35925 - MD5:
fcfec3287613281e93ffa8e10d9c6803 - ssdeep:
768:ugGzpDpne0kK051drQUeQVIAVPE1E/biCD2UuhdpxLPYFz31x/uV1z4CVKJbe7VO:LGFheVP6Caxn2J3nGLkCVK6uc50D - TLSH:
T165348EF35097DD8C7AC7AB1369BB2025158AC74C2136DBA0488C7A6DD5BC6BD6E00E60 - Submitted as: gixisavusapijunerifetap.pdf
- File type: pdf · Size: 52622 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=asset+disposal+account+pdf, https://cdn-cms.f-static.net/uploads/4367938/normal_5f876c1169098.pdf, https://cdn-cms.f-static.net/uploads/4368265/normal_5f8771d2c3c94.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=asset+disposal+account+pdf
- https://cdn-cms.f-static.net/uploads/4367938/normal_5f876c1169098.pdf
- https://cdn-cms.f-static.net/uploads/4368265/normal_5f8771d2c3c94.pdf
- https://cdn-cms.f-static.net/uploads/4366647/normal_5f876607841b9.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f87ca4ea3082.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f87aff11b3ef.pdf
- https://uploads.strikinglycdn.com/files/12296ac3-eb34-41b3-81a6-5fa763190d12/sadufokusoteruf.pdf
- https://uploads.strikinglycdn.com/files/4278a3f9-10d6-4423-9826-fe75c4c7e84f/24709271269.pdf
- https://uploads.strikinglycdn.com/files/548630fd-c4b6-4706-bf93-635077775930/wosukepor.pdf
- https://uploads.strikinglycdn.com/files/a29aca18-6e70-4f1b-9af9-233b15d47dbe/20387744211.pdf
- https://uploads.strikinglycdn.com/files/a1d7f989-1a91-45fe-8bda-0558159481b7/penuzarixopilifowalomilaz.pdf
- https://site-1048260.mozfiles.com/files/1048260/39747774976.pdf
- https://site-1039833.mozfiles.com/files/1039833/gafisetovodutimafod.pdf
- https://cdn.shopify.com/s/files/1/0496/6567/1325/files/mutuwenunor.pdf
- https://cdn.shopify.com/s/files/1/0433/0009/4112/files/vojodigopipatakute.pdf
- https://cdn.shopify.com/s/files/1/0437/4216/7189/files/luces_de_bohemia_resumen_selectividad.pdf
- https://cdn.shopify.com/s/files/1/0496/5875/7277/files/13759575078.pdf
- https://cdn.shopify.com/s/files/1/0479/4889/0268/files/wovifimepezej.pdf
- https://uploads.strikinglycdn.com/files/2171a214-eae1-4ecf-ac8c-6907f4db0189/84940647029.pdf
- https://uploads.strikinglycdn.com/files/127cf1c6-79b4-4c47-95ac-6212619fcafe/26402959611.pdf
- https://uploads.strikinglycdn.com/files/8089aaad-4905-437d-90bb-271e8d9ee489/sifukaki.pdf
- https://uploads.strikinglycdn.com/files/2e485881-3d1a-4945-b74f-b1936fcc69d6/xipevizoxoxosoxedix.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1048260.mozfiles.com
- site-1039833.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report