SUSPICIOUS — gejakozefa.pdf
SUSPICIOUS — gejakozefa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
d0cf1419b666cb83c229b15d849544f055b7faa1bc357f9f3917adda2043725d - SHA-1:
9a710817cf20770ffc5b132700b21cb5dc1be839 - MD5:
3d170dd891de681a2a0b662b7d7d4b01 - ssdeep:
1536:pGFcrR1UPUNI38P+dITatM5QbcKW2LC7A+eRL1+:8FcrRDn+dJtGz52m7FeRw - TLSH:
T12936C0F350A7DC8C7AC68F43ADAA249E6096974D3032EA6411D9BB6CC47C3BD5E40E50 - Submitted as: gejakozefa.pdf
- File type: pdf · Size: 68832 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=delhi+metro+map+pdf+download+hd, https://uploads.strikinglycdn.com/files/4050184e-50fc-483f-88dd-fb7bb22f2577/relotomafelof.pdf, https://uploads.strikinglycdn.com/files/299148e8-6a25-444c-bab0-2402900b6207/mevalobuziwatufuturadib.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=delhi+metro+map+pdf+download+hd
- https://uploads.strikinglycdn.com/files/4050184e-50fc-483f-88dd-fb7bb22f2577/relotomafelof.pdf
- https://uploads.strikinglycdn.com/files/299148e8-6a25-444c-bab0-2402900b6207/mevalobuziwatufuturadib.pdf
- https://uploads.strikinglycdn.com/files/6ea4e596-b5f9-485c-8ea5-3f3e8e0b3852/40748751412.pdf
- http://fatup.imagemaycontain.com/uploads/1/3/1/1/131163943/xunoz.pdf
- http://files.capeannbiblechurch.org/uploads/1/3/0/7/130776247/pisuwidulapuvazolim.pdf
- http://sukejot.mesabimusicaltheater.com/uploads/1/3/1/3/131383483/mudaroveragiwor.pdf
- http://files.lafayetteschoolrestoration.com/uploads/1/3/1/3/131398357/nutuva.pdf
- http://files.mowtakoma.org/uploads/1/3/1/4/131438449/xizedaworisomu_misuroxep.pdf
- http://files.curealldiseasenow.com/uploads/1/3/1/4/131406662/risubeju.pdf
- http://files.conservalion.com/uploads/1/3/0/9/130969472/jovebuj.pdf
- http://files.amcskokie.com/uploads/1/3/1/3/131398338/7252fe9a838e0.pdf
- http://rolugis.richardaoun.com/uploads/1/3/1/4/131437092/piwuzev.pdf
- http://vuxopad.medtechwearables.com/uploads/1/3/1/3/131379730/7769098.pdf
- http://files.cbccabinets.com/uploads/1/3/1/6/131606835/dumobevekudugo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- fatup.imagemaycontain.com
- files.capeannbiblechurch.org
- sukejot.mesabimusicaltheater.com
- files.lafayetteschoolrestoration.com
- files.mowtakoma.org
- files.curealldiseasenow.com
- files.conservalion.com
- files.amcskokie.com
- rolugis.richardaoun.com
- vuxopad.medtechwearables.com
- files.cbccabinets.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report