SUSPICIOUS — gakimagerog.pdf
SUSPICIOUS — gakimagerog.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4ca88c2fc2e537de74f25fc3afcafff8ceb7a9d4800bd26b590cdcc25346aa62 - SHA-1:
634e788d206dc67e07f7f33b71d2a938597c763f - MD5:
4d1506cc16eaab7795c0f60845653f26 - ssdeep:
768:cgGzpDcd20CpXgySKgOrA8pI4SHBnb/QYF2GG1616mKK9/5DgEmEblSr7:5GFwZpK7rNp2EYuA16rK9+EmEbl87 - TLSH:
T153329FF31097FD8C3E8A6B53EAE60549218EC788A132E66054CC776DC47C6BC7E10A61 - Submitted as: gakimagerog.pdf
- File type: pdf · Size: 46750 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=archimedean+solids+templates+pdf, https://cdn.shopify.com/s/files/1/0435/2969/9482/files/toniwadaribopaxikasod.pdf, https://cdn.shopify.com/s/files/1/0460/6820/3675/files/mevupekolinurapizavit.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=archimedean+solids+templates+pdf
- https://cdn.shopify.com/s/files/1/0435/2969/9482/files/toniwadaribopaxikasod.pdf
- https://cdn.shopify.com/s/files/1/0460/6820/3675/files/mevupekolinurapizavit.pdf
- https://cdn.shopify.com/s/files/1/0485/7443/1392/files/6782097906.pdf
- https://cdn.shopify.com/s/files/1/0440/3773/4550/files/grammar_games_and_activities_for_teachers_peter_watcyn_jones.pdf
- https://uploads.strikinglycdn.com/files/aec1d35f-0e8a-432b-9556-dd5a18f379a5/xevutatiboxev.pdf
- https://uploads.strikinglycdn.com/files/f301e439-7091-4dd0-a959-3ca5e4c4b68e/86789086593.pdf
- https://uploads.strikinglycdn.com/files/fc9ab916-2d20-40bd-8437-be9db321c245/jizijalipisu.pdf
- https://uploads.strikinglycdn.com/files/48c9fe8d-08fc-4ae6-83a8-694193a2ecad/wowiligixebafedubezo.pdf
- https://uploads.strikinglycdn.com/files/bef974e3-6f79-4885-ae1b-c8f34383afe7/13299390754.pdf
- https://uploads.strikinglycdn.com/files/50009491-f3d7-4564-8b05-416026eca883/jesozefuze.pdf
- https://uploads.strikinglycdn.com/files/caf1ce5b-6346-4764-a12a-4d03ca04d9f6/wamepetobixakefesaxinib.pdf
- https://uploads.strikinglycdn.com/files/aa660577-7e93-44c1-9ea0-2536c7d53832/69896450572.pdf
- http://files.professorwmoser.com/uploads/1/3/0/9/130969987/3437644.pdf
- http://files.ebchinese.org/uploads/1/3/0/7/130740458/jerutesupimukiz.pdf
- http://files.lifefurandadventure.com/uploads/1/3/1/4/131411199/goboku.pdf
- http://gibozil.amazingauctions.us/uploads/1/3/0/8/130814017/benitukeg_jukamer_wuwepaminogepo_lalemi.pdf
- http://files.dispensinglink.com/uploads/1/3/1/3/131398517/7bfc8.pdf
- https://en.wikipedia.org/w/index.php?title=Template:Archimedean_solids&
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- files.professorwmoser.com
- files.ebchinese.org
- files.lifefurandadventure.com
- gibozil.amazingauctions.us
- files.dispensinglink.com
- en.wikipedia.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report