MALICIOUS — gekofelosovimekagaro.pdf
MALICIOUS — gekofelosovimekagaro.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9815b3cdea83db69c3a16da8a2c8c3d25ec1e108dd049c0936b907a5e6e0a7dc - SHA-1:
4715e76a6784c345f033f9a1df729a30591819e6 - MD5:
7fd151a2402a6050d612a0b245cf143c - ssdeep:
768:FgGzpDYpP2xTM87CAL5gXiJMjsdmc8+k0lLcHSWlN8N73SpLOCt+HKTlOqOjxXjE:WGFMpu6l+jbvbmNtjkdXKXKON - TLSH:
T150328EF300D7ED8D7B4F5B03ADA7109A554AE7499137DBA0448C6B2CD0BC6ADBE50910 - Submitted as: gekofelosovimekagaro.pdf
- File type: pdf · Size: 43508 bytes
- Verdict: malicious (70/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://ggtraff.ru/wb?keyword=camp%20camp%20max%20x%20nikki, https://cdn-cms.f-static.net/uploads/4366045/normal_5f86f9400c3ee.pdf, https://cdn-cms.f-static.net/uploads/4365639/normal_5f86f462378d1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=camp%20camp%20max%20x%20nikki
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f86f9400c3ee.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f86f462378d1.pdf
- https://cdn-cms.f-static.net/uploads/4366639/normal_5f8727b9a20e5.pdf
- https://cdn-cms.f-static.net/uploads/4366367/normal_5f87140bdc887.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f8714cde92d2.pdf
- https://cdn-cms.f-static.net/uploads/4366676/normal_5f871c6d65867.pdf
- https://cdn-cms.f-static.net/uploads/4365624/normal_5f871420f2552.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f870a613e7bc.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f86fe7512fd6.pdf
- https://site-1038530.mozfiles.com/files/1038530/35966784237.pdf
- https://site-1039163.mozfiles.com/files/1039163/8430902958.pdf
- https://site-1042619.mozfiles.com/files/1042619/91322800109.pdf
- https://site-1039743.mozfiles.com/files/1039743/bibabegorurif.pdf
- https://site-1040509.mozfiles.com/files/1040509/62464762664.pdf
- https://uploads.strikinglycdn.com/files/84ee43a7-44f1-4692-8e74-27268449e9fd/muritonabo.pdf
- https://uploads.strikinglycdn.com/files/c73f0bc0-c9e6-4b2f-a205-3eec60adf5a3/40118773973.pdf
- https://uploads.strikinglycdn.com/files/8ababc51-9886-40e2-9710-e664c5faea5b/kupajad.pdf
- https://uploads.strikinglycdn.com/files/5d54a632-68df-4ee2-9e14-817900d53d07/zinujopiweginukudomin.pdf
- https://uploads.strikinglycdn.com/files/ae419571-c9fd-4901-b851-385b7450fd78/73227356109.pdf
- https://cdn.shopify.com/s/files/1/0467/9837/3013/files/17790518330.pdf
- https://cdn.shopify.com/s/files/1/0500/4876/2016/files/black_and_decker_mouse_sander_troubleshooting.pdf
- https://cdn.shopify.com/s/files/1/0478/1670/4159/files/2013_form_1042.pdf
- https://cdn.shopify.com/s/files/1/0429/6579/4969/files/2787505189.pdf
- https://cdn.shopify.com/s/files/1/0494/2263/1067/files/236980766.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1038530.mozfiles.com
- site-1039163.mozfiles.com
- site-1042619.mozfiles.com
- site-1039743.mozfiles.com
- site-1040509.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report