SUSPICIOUS — goxodofiv.pdf
SUSPICIOUS — goxodofiv.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
72a30ad760681eeb92a0edcfa5e6b52175d63d4fb015a2ad0d60aa1842350e6f - SHA-1:
0eaeaeca980c0a7a061fdaaf1ad98503d46f6907 - MD5:
2490ac807c4c8c1e1eddcc5b27b36e89 - ssdeep:
768:0gGzpDzfdRBljGVlSB0ATEi2rG4fQz/O319ZOuammCd3zS3u8U7apn:BGF/1iYv4fQz/10mCd3z0u8U7apn - TLSH:
T198329DF31097ED8D7A8ABB139EBF115D6089C68C6136A76009CC7B6DC4BC6ED5E04A10 - Submitted as: goxodofiv.pdf
- File type: pdf · Size: 43807 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=plywood+boat+plans+pram, https://uploads.strikinglycdn.com/files/2b7e077c-3086-4d52-adcd-1eeae0d9497e/kesokadagaxod.pdf, https://uploads.strikinglycdn.com/files/6c9f26b2-89e3-4c19-9e73-1edfd5e6218a/sibelatajowibudo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=plywood+boat+plans+pram
- https://uploads.strikinglycdn.com/files/2b7e077c-3086-4d52-adcd-1eeae0d9497e/kesokadagaxod.pdf
- https://uploads.strikinglycdn.com/files/6c9f26b2-89e3-4c19-9e73-1edfd5e6218a/sibelatajowibudo.pdf
- https://uploads.strikinglycdn.com/files/50ad98a5-75d3-4197-89c9-07bdcdfb5ebb/27540990070.pdf
- https://uploads.strikinglycdn.com/files/3b89abc3-4901-4bac-8436-584fac6778c4/83351328834.pdf
- https://uploads.strikinglycdn.com/files/a1929d7a-5446-44b8-abf3-9730ab571412/92695014909.pdf
- http://files.chagrinvalleywellness.com/uploads/1/3/0/7/130739043/6070951.pdf
- http://golufewig.pattystewartandassociates.com/uploads/1/3/2/7/132740515/jitip.pdf
- http://files.ntpfx.com/uploads/1/3/2/7/132740339/vizixebexowemow.pdf
- http://files.gleteacher.net/uploads/1/3/1/4/131453456/movapibanupoxem.pdf
- http://tedegu.inspiredfictionbooks.com/uploads/1/3/0/9/130969198/9371783.pdf
- https://cdn.shopify.com/s/files/1/0434/4823/8241/files/josinopureka.pdf
- https://cdn.shopify.com/s/files/1/0431/5843/8039/files/puxizo.pdf
- https://uploads.strikinglycdn.com/files/cedaec40-98cd-46ac-ab7e-74a896e6423f/89557726197.pdf
- https://uploads.strikinglycdn.com/files/781cbd87-35f8-4c78-9a77-6b54ab0321a0/mobep.pdf
- https://uploads.strikinglycdn.com/files/ff3792c1-70c7-4243-9d52-81acf1cac361/dobusomavonevelitometa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.chagrinvalleywellness.com
- golufewig.pattystewartandassociates.com
- files.ntpfx.com
- files.gleteacher.net
- tedegu.inspiredfictionbooks.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report