SUSPICIOUS — dajowonusinevogabu.pdf
SUSPICIOUS — dajowonusinevogabu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c9bb33760f9c1f3154e2b5e464cc7e1e7bb62bb6ecabb99395147708abc156eb - SHA-1:
b67d3aa7d813ab301538eb97807bca79de8f3cd7 - MD5:
d353213fae78a3a72e5a8574c83f9d15 - ssdeep:
1536:zGFGqSHp5mVtMsI2lnXRo9lTDxxTuY4uSGN1qIUx2u:CFGqG5CV09D7TuY4qNzU5 - TLSH:
T14F37C0F390A3ED4CBE966B075DAA1298104AD34D6172E7B054C93B2DD03C2FDAF50626 - Submitted as: dajowonusinevogabu.pdf
- File type: pdf · Size: 70811 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=synopsys+vcs+user+guide+2017, https://site-1036956.mozfiles.com/files/1036956/46906227181.pdf, https://site-1036652.mozfiles.com/files/1036652/zaxize.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=synopsys+vcs+user+guide+2017
- https://site-1036956.mozfiles.com/files/1036956/46906227181.pdf
- https://site-1036652.mozfiles.com/files/1036652/zaxize.pdf
- https://site-1037205.mozfiles.com/files/1037205/14090704491.pdf
- https://site-1042287.mozfiles.com/files/1042287/vitapegatozazozopidabapeg.pdf
- https://site-1037224.mozfiles.com/files/1037224/bobinorafezut.pdf
- https://site-1036918.mozfiles.com/files/1036918/79238276025.pdf
- https://site-1039752.mozfiles.com/files/1039752/wegugipovinodareja.pdf
- https://site-1038558.mozfiles.com/files/1038558/36061390359.pdf
- https://site-1036946.mozfiles.com/files/1036946/4727244989.pdf
- http://bepel.positivescanning.com/uploads/1/3/0/7/130775897/vafonobo_wusuwesado_xesar_dubaziz.pdf
- http://files.elchristian.org/uploads/1/3/1/4/131454916/zuzis.pdf
- http://kobabik.abcburglaralarm.com/uploads/1/3/0/7/130775034/a6ae162a279dff0.pdf
- http://zuvefanim.laciavogel.com/uploads/1/3/1/4/131438583/d7558a5957a.pdf
- http://files.ollieboormandrumacademy.com/uploads/1/3/0/7/130740242/gosofimukatuzete.pdf
- https://cdn.shopify.com/s/files/1/0484/0459/4856/files/75450302068.pdf
- https://cdn.shopify.com/s/files/1/0432/6693/2902/files/rikimategapon.pdf
- https://cdn.shopify.com/s/files/1/0481/4222/1463/files/planet_fitness_warwick_ny.pdf
- https://cdn.shopify.com/s/files/1/0437/9371/1265/files/87555861931.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036956.mozfiles.com
- site-1036652.mozfiles.com
- site-1037205.mozfiles.com
- site-1042287.mozfiles.com
- site-1037224.mozfiles.com
- site-1036918.mozfiles.com
- site-1039752.mozfiles.com
- site-1038558.mozfiles.com
- site-1036946.mozfiles.com
- bepel.positivescanning.com
- files.elchristian.org
- kobabik.abcburglaralarm.com
- zuvefanim.laciavogel.com
- files.ollieboormandrumacademy.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report