SUSPICIOUS — gemelag.pdf
SUSPICIOUS — gemelag.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
c1eec834b4a33e8022136efcdfba7651dc603b2c4f4f64809fc4112c6cf4fa31 - SHA-1:
d5f28e107b21afc51f9c5691e01716324af2bc37 - MD5:
44c560024c1df67c2e5a62d4a1802410 - ssdeep:
768:8gGzpDEa0785yVCBE/qStNSeI7LHZkacYfPFVly6O7i0RLrD09G:ZGFIa4iOtNSx5jcYf9VREiWrD0I - TLSH:
T1A431AFF340A3DD4C7A8AAF0BAEE610596149D74C2136A7A048887B2DC47C7FD7E10E56 - Submitted as: gemelag.pdf
- File type: pdf · Size: 42917 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=convert+scanned+pdf+to+editable+word+free+online, https://site-1037266.mozfiles.com/files/1037266/26616020391.pdf, https://site-1037169.mozfiles.com/files/1037169/dagizozebedafiretujibalam.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=convert+scanned+pdf+to+editable+word+free+online
- https://site-1037266.mozfiles.com/files/1037266/26616020391.pdf
- https://site-1037169.mozfiles.com/files/1037169/dagizozebedafiretujibalam.pdf
- https://site-1040282.mozfiles.com/files/1040282/dazewovodibalirubowive.pdf
- https://site-1037085.mozfiles.com/files/1037085/wojogu.pdf
- https://site-1039797.mozfiles.com/files/1039797/2987451481.pdf
- https://uploads.strikinglycdn.com/files/cebc0886-2025-495f-bc95-0d2090ff91d4/jamukawokukujawan.pdf
- https://uploads.strikinglycdn.com/files/266e8da9-b31f-4248-9e61-ec99500ba01c/xezibanajaxogosetorozawa.pdf
- https://uploads.strikinglycdn.com/files/3a0aba0a-7cee-4f45-acb7-038141529a79/dadugo.pdf
- https://uploads.strikinglycdn.com/files/14866fd3-1275-49ee-92b0-1a0b7e6a1721/logabujofozuw.pdf
- https://site-1037035.mozfiles.com/files/1037035/vepuminibade.pdf
- https://site-1037212.mozfiles.com/files/1037212/nodemusoziditabogexasuwi.pdf
- https://uploads.strikinglycdn.com/files/1632ef0d-d869-4473-b2ff-c0b44b5bce87/nejugonibadukepomoveteram.pdf
- https://uploads.strikinglycdn.com/files/ae41a8be-1ccc-41e8-b542-d9a34fa34624/rorevovagagiweg.pdf
- https://uploads.strikinglycdn.com/files/28b321b0-3d8b-4102-9409-9b226427de0e/56120542386.pdf
- https://uploads.strikinglycdn.com/files/9745e7e5-ee76-4256-bd05-8d72540f54c5/vojekeditoded.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037266.mozfiles.com
- site-1037169.mozfiles.com
- site-1040282.mozfiles.com
- site-1037085.mozfiles.com
- site-1039797.mozfiles.com
- uploads.strikinglycdn.com
- site-1037035.mozfiles.com
- site-1037212.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report