SUSPICIOUS — gelogerubusef_dikanisavubef.pdf
SUSPICIOUS — gelogerubusef_dikanisavubef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
caac026110d55a658c79ef3b3af41e398b4e5ed5abe1d66f923ecba437404a21 - SHA-1:
495e3ac455b1711da8e949a8113911ab80bbff20 - MD5:
c4066c45f36e1de95a2aa27af3d8b0e8 - ssdeep:
768:/gGzpD/pDbY7TGdb+Y4NZqnv/7Pk4gF2rsy/BFHBpB8m6nd4I21qXO:IGFjp7qHM1/LBcm6zqqXO - TLSH:
T1CD316CF35097ED8C7A8F6F13AEAF016E554AC78C613697605188761CD0BCAFD2E10A12 - Submitted as: gelogerubusef_dikanisavubef.pdf
- File type: pdf · Size: 42078 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=conflicts%20in%20lord%20of%20the%20flies, https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/5912560.pdf, https://xavoxoxuda.weebly.com/uploads/1/3/1/3/131379246/1da7ccef7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=conflicts%20in%20lord%20of%20the%20flies
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/5912560.pdf
- https://xavoxoxuda.weebly.com/uploads/1/3/1/3/131379246/1da7ccef7.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/vofav_pugakam_bijijufajanonip.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f88afd5c218c.pdf
- https://cdn-cms.f-static.net/uploads/4379855/normal_5f8e086faecb0.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f89fbe760b3a.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f875517e4465.pdf
- https://cdn-cms.f-static.net/uploads/4377662/normal_5f8d3a80b3475.pdf
- https://uploads.strikinglycdn.com/files/751555e5-7cf4-4704-9ec6-69a1a7311b34/downloadsnack_password.txt_1.4_kb.pdf
- https://uploads.strikinglycdn.com/files/534ff6bf-8316-4406-8f24-79c1ffd66e49/10360161671.pdf
- https://uploads.strikinglycdn.com/files/85a9bb1a-11c9-464f-af7d-7a820e09e2d0/the_lightning_thief_graphic_novel_read_online_free.pdf
- https://uploads.strikinglycdn.com/files/cc9ef08f-1b2e-4da1-abf3-438ebce272b3/39438173142.pdf
- https://uploads.strikinglycdn.com/files/fc6355bd-5212-4d0c-a181-c71f76518c65/45486935145.pdf
- https://cdn-cms.f-static.net/uploads/4366620/normal_5f89eb81d7d66.pdf
- https://cdn-cms.f-static.net/uploads/4377400/normal_5f8b27be6850e.pdf
- https://cdn.shopify.com/s/files/1/0493/1744/5791/files/candy_crush_saga_gold_bars_hack.pdf
- https://cdn.shopify.com/s/files/1/0478/1791/6575/files/govefaxejosizibi.pdf
- https://cdn.shopify.com/s/files/1/0480/7481/7693/files/98331066643.pdf
- https://cdn.shopify.com/s/files/1/0500/5328/4008/files/gumifi.pdf
- https://cdn.shopify.com/s/files/1/0479/2244/6492/files/tebekijopuwoxanadu.pdf
- https://cdn.shopify.com/s/files/1/0499/8837/0582/files/basics_of_economics_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0500/2513/6278/files/kuxadufaworolifobum.pdf
- https://cdn.shopify.com/s/files/1/0431/1616/7328/files/genie_g3t_remote_manual.pdf
- https://cdn.shopify.com/s/files/1/0484/7091/7282/files/how_to_turn_garageband_file_into_mp3_iphone.pdf
Embedded domains
- gettraff.ru
- fekudumubaf.weebly.com
- xavoxoxuda.weebly.com
- bedizegoresupa.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report