SUSPICIOUS — gafodokemedalevib.pdf
SUSPICIOUS — gafodokemedalevib.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ac23da38d59b95835243a94e8535b27ce52b89dd495a5c41de81d5f1cf745892 - SHA-1:
e3b28425a8e7e4e0eee89b89dcc15e79fcc01795 - MD5:
d77c8946811f7b4d8262128fbc8ae701 - ssdeep:
768:ogGzpD3p4tMrycdQDgKl+EbnuPQkSyRp4zv+SqsbKFpwbb4rqKviu:lGFTpI/+InuPTSSSvKFybpKviu - TLSH:
T133328DF310A7ED8CBB4F5B43ADAB1269508AC749A162EB50058C6B2CD5BC6FD6F00911 - Submitted as: gafodokemedalevib.pdf
- File type: pdf · Size: 46557 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/baf6b302-9399-46f9-bd24-1c2ca5f865b7/zuwazovovagexeno.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=chaos+codex+2, https://cdn.shopify.com/s/files/1/0431/2842/2566/files/kusorajokikabidasa.pdf, https://cdn.shopify.com/s/files/1/0479/7248/3228/files/gekorovimifuvalavej.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=chaos+codex+2
- https://cdn.shopify.com/s/files/1/0431/2842/2566/files/kusorajokikabidasa.pdf
- https://cdn.shopify.com/s/files/1/0479/7248/3228/files/gekorovimifuvalavej.pdf
- https://cdn.shopify.com/s/files/1/0497/8229/2629/files/makalah_kompetensi_guru.pdf
- https://cdn.shopify.com/s/files/1/0433/2044/3045/files/bulatezokuzofusata.pdf
- https://uploads.strikinglycdn.com/files/baf6b302-9399-46f9-bd24-1c2ca5f865b7/zuwazovovagexeno.pdf
- https://uploads.strikinglycdn.com/files/6973b3b5-7d39-48c9-a6ac-493ff12f2835/jomezusuxelatamijap.pdf
- https://uploads.strikinglycdn.com/files/8adbcd94-9ab7-4490-b6d1-5d4f2a5cf242/93655528473.pdf
- https://uploads.strikinglycdn.com/files/f57a5dce-5e5b-4409-9569-a67c534fcdf3/wiloritewowow.pdf
- https://uploads.strikinglycdn.com/files/207fa648-cadb-4fe9-9b6c-9b6ef738afb3/68760995394.pdf
- https://cdn.shopify.com/s/files/1/0496/2307/2921/files/43222866108.pdf
- https://cdn.shopify.com/s/files/1/0496/2608/7575/files/94995022279.pdf
- https://cdn.shopify.com/s/files/1/0479/4702/2492/files/botabimidejepuwe.pdf
- https://cdn.shopify.com/s/files/1/0460/2019/8559/files/80942863746.pdf
- https://gibitiwatu.weebly.com/uploads/1/3/0/7/130776060/7553062.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/wowisufogu.pdf
- https://korodaziso.weebly.com/uploads/1/3/0/7/130740443/9306334.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/runemevurexuziwone.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/faf657a0e.pdf
- https://cdn-cms.f-static.net/uploads/4368486/normal_5f8a51e282ab9.pdf
- https://cdn-cms.f-static.net/uploads/4383295/normal_5f8bdbbcd1a63.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/vibururodiz.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/jimoroxojed_xifojavar_silazekaludita.pdf
- https://genamimiwovem.weebly.com/uploads/1/3/1/6/131636881/804e16449ed9fd.pdf
- https://sonilotosoj.weebly.com/uploads/1/3/1/3/131379329/jigekuzileketed.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- gibitiwatu.weebly.com
- nanorobudilason.weebly.com
- korodaziso.weebly.com
- genigudepa.weebly.com
- vodipewelo.weebly.com
- cdn-cms.f-static.net
- papunagaku.weebly.com
- rimesozarabef.weebly.com
- genamimiwovem.weebly.com
- sonilotosoj.weebly.com
- kokubexajaluk.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report