SUSPICIOUS — gifofuwegegemovab.pdf
SUSPICIOUS — gifofuwegegemovab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3ecdc1c26ff6e0ee9abe0294430b6e7ebef372512915e3d177c87139d687c250 - SHA-1:
2e96e970edbeb65badc6fa7340d99da76c8dbc5c - MD5:
4ef3c8a3679e320e57ba640c5b2c000e - ssdeep:
768:igGzpD28OfG9GB/4+u8MTpD+F+GizFksylQ1QEO00Ff1af7uf2eDW2j:/GFKRv4nD+kGiz3ylQmEkF9af7uf2eDJ - TLSH:
T14532BFF344ABDE4C7E899F07ACAA04556586C39C7133E7B018D87B6CD4BC5AD6E008A1 - Submitted as: gifofuwegegemovab.pdf
- File type: pdf · Size: 45432 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=atlas+de+anatomia+y+fisiologia+humana, https://cdn.shopify.com/s/files/1/0497/2252/3805/files/tozaba.pdf, https://cdn.shopify.com/s/files/1/0493/0682/8959/files/why_dont_jehovahs_witnesses_celebrate_birthdays_reddit.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=atlas+de+anatomia+y+fisiologia+humana
- https://cdn.shopify.com/s/files/1/0497/2252/3805/files/tozaba.pdf
- https://cdn.shopify.com/s/files/1/0493/0682/8959/files/why_dont_jehovahs_witnesses_celebrate_birthdays_reddit.pdf
- https://cdn.shopify.com/s/files/1/0441/1362/5240/files/kilusifawuxiluke.pdf
- https://cdn.shopify.com/s/files/1/0438/5911/6182/files/sinjid_shadow_of_the_warrior_guide.pdf
- http://nomaviri.ecriturestl.org/uploads/1/3/0/7/130740055/pinini.pdf
- http://files.freedive305.com/uploads/1/3/1/4/131408153/3465683.pdf
- http://files.nobbysyoga.com/uploads/1/3/0/9/130969494/jesolinimo.pdf
- https://site-1036830.mozfiles.com/files/1036830/muwajigiside.pdf
- https://site-1037022.mozfiles.com/files/1037022/lezarasag.pdf
- https://site-1039873.mozfiles.com/files/1039873/7681888111.pdf
- https://site-1036815.mozfiles.com/files/1036815/36669280044.pdf
- https://site-1038750.mozfiles.com/files/1038750/kosawapurero.pdf
- https://cdn.shopify.com/s/files/1/0496/7717/2889/files/34863593287.pdf
- https://cdn.shopify.com/s/files/1/0457/7463/5174/files/jojonob.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- nomaviri.ecriturestl.org
- files.freedive305.com
- files.nobbysyoga.com
- site-1036830.mozfiles.com
- site-1037022.mozfiles.com
- site-1039873.mozfiles.com
- site-1036815.mozfiles.com
- site-1038750.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report