SUSPICIOUS — latixedadexagijevepo.pdf
SUSPICIOUS — latixedadexagijevepo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5a14cb074b997e937108d908174638424699ad47b312e04e802035e03b5415fc - SHA-1:
8c1b018277bc822bacd9212f58ebf749029b6935 - MD5:
00b1a6a1a8e4683bef1c0502503e113a - ssdeep:
768:9gGzpD8MUN24QJAmvFg52S1UgKNTm1M/Par64CGuH83+D3j:+GFoF042AAFjMUgU/Pk644H83+D3j - TLSH:
T1A4329EF300A7ED4C7ACBAB43ADAA1459904AD34C613697A018C8776CD4BCAED7F40E51 - Submitted as: latixedadexagijevepo.pdf
- File type: pdf · Size: 45295 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=gst+return+details+in+hindi+pdf, https://site-1036728.mozfiles.com/files/1036728/dikizuxeno.pdf, https://site-1036902.mozfiles.com/files/1036902/71950570356.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=gst+return+details+in+hindi+pdf
- https://site-1036728.mozfiles.com/files/1036728/dikizuxeno.pdf
- https://site-1036902.mozfiles.com/files/1036902/71950570356.pdf
- https://site-1037019.mozfiles.com/files/1037019/97284002255.pdf
- https://site-1036728.mozfiles.com/files/1036728/rorovigamojiwupofufobotis.pdf
- https://site-1037883.mozfiles.com/files/1037883/guxagiridijemiranarotaxe.pdf
- https://uploads.strikinglycdn.com/files/26bcd06e-5e0b-4f04-9ac8-0ccc98431302/tezikojatutepogitiga.pdf
- https://uploads.strikinglycdn.com/files/037e3120-364a-4cfb-b500-1a5482b1a03b/53951626998.pdf
- https://uploads.strikinglycdn.com/files/4f18562e-83eb-4b17-b5c0-189da0a5c0d9/kufovaxexeburexezig.pdf
- https://uploads.strikinglycdn.com/files/2906d18b-3a84-474e-8f4e-c0b65c59be07/68691972381.pdf
- https://uploads.strikinglycdn.com/files/4c9fdd44-ef44-45a3-a1aa-a590930eec5e/36929628591.pdf
- http://zozalivo.nwpc-tx.com/uploads/1/3/1/4/131453565/4810477.pdf
- http://files.mostmiserablemusical.com/uploads/1/3/2/6/132696030/bilagaxiluka-wikojovas-wazamalotemef.pdf
- http://gevuka.ultimatefantasyfighting.com/uploads/1/3/1/3/131380433/tozubexazani-basigudasuj-duvekidazagin.pdf
- http://goleji.annawitte.org/uploads/1/3/0/7/130776367/48aa61.pdf
- https://cdn.shopify.com/s/files/1/0435/6440/0798/files/90049103749.pdf
- https://cdn.shopify.com/s/files/1/0431/1675/7153/files/65140501257.pdf
- https://cdn.shopify.com/s/files/1/0438/2189/1746/files/hp_bcm20702a0_driver_free.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036728.mozfiles.com
- site-1036902.mozfiles.com
- site-1037019.mozfiles.com
- site-1037883.mozfiles.com
- uploads.strikinglycdn.com
- zozalivo.nwpc-tx.com
- files.mostmiserablemusical.com
- gevuka.ultimatefantasyfighting.com
- goleji.annawitte.org
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report