SUSPICIOUS — girinu.pdf
SUSPICIOUS — girinu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4bb5f68155bcd2689cc9eff81d3b518b4b66bd3eaabf70e07c5f9264501073c7 - SHA-1:
1800245ab5363b3371481fc68be4202734afa5b8 - MD5:
63dc54abf78d1fcf4c956eb867bf6305 - ssdeep:
768:igGzpDb4F3AmXfzN3JfExKrIcGkPzrMNn4eWHlhwY9y3EZL2cr+oujrz1Zk+Jaev:/GFHw7NgNn4eonU0Kc6ou3znki6du - TLSH:
T1F333BFF340ABDCCC6A877F476EE604AA2105E34D6136A76458987B6CC4783FE6F10921 - Submitted as: girinu.pdf
- File type: pdf · Size: 49923 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=after+effects+cs5+tutorials+pdf, http://kolanugo.runnxc.com/uploads/1/3/1/4/131452977/gujafobakizapil.pdf, http://kogaxo.generalchemistrythames.com/uploads/1/3/0/9/130969663/0a648c51f71f6.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=after+effects+cs5+tutorials+pdf
- http://kolanugo.runnxc.com/uploads/1/3/1/4/131452977/gujafobakizapil.pdf
- http://kogaxo.generalchemistrythames.com/uploads/1/3/0/9/130969663/0a648c51f71f6.pdf
- http://files.amjetaviation.com/uploads/1/3/0/7/130739525/vusasonal_dagiwoseb.pdf
- https://cdn.shopify.com/s/files/1/0429/2568/6951/files/75601884228.pdf
- https://cdn.shopify.com/s/files/1/0478/6352/9638/files/digestion_of_carbohydrates_in_small_intestine.pdf
- https://cdn.shopify.com/s/files/1/0437/2883/0632/files/37773386321.pdf
- https://cdn.shopify.com/s/files/1/0431/3759/7591/files/suwadubodorevevojofumudok.pdf
- https://cdn.shopify.com/s/files/1/0429/5006/6339/files/koganunisa.pdf
- https://cdn.shopify.com/s/files/1/0428/8787/2671/files/80760878046.pdf
- https://cdn.shopify.com/s/files/1/0483/8303/3501/files/jelafel.pdf
- https://cdn.shopify.com/s/files/1/0482/6795/2290/files/godubunexepatawaxasejesuj.pdf
- https://cdn.shopify.com/s/files/1/0482/2941/7112/files/simple_and_sinister_warm_up.pdf
- http://files.richmullins.candletothesun.com/uploads/1/3/1/4/131483305/c9906da4ff2.pdf
- http://files.dublintaiko.com/uploads/1/3/1/4/131438077/1504851.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- kolanugo.runnxc.com
- kogaxo.generalchemistrythames.com
- files.amjetaviation.com
- cdn.shopify.com
- files.richmullins.candletothesun.com
- files.dublintaiko.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report