MALICIOUS — sudovonekexip.pdf
MALICIOUS — sudovonekexip.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
d67abf490b2a5f8792077e58c09910588bb1f4788878f150826efe39b6fc113a - SHA-1:
fe2cbb4b65dbd39db5ae53c75e536b0b075ddf0e - MD5:
a35b8783e93ed687b42a589fe73ebd75 - ssdeep:
768:YgGzpDuXKCjYJvkgbgt6AIsxNy7cuVAv3n+vxeFaK9B:1GFKXBgshI8g7cuCv3DF99B - TLSH:
T17B329FF35097ED8C778FAF135EA31258618AD38C6136925008DCB72DD5BC6ED2E10A54 - Submitted as: sudovonekexip.pdf
- File type: pdf · Size: 44192 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.PDF.Agent.gen (rule
HEUR:Trojan.PDF.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ggtraff.ru/strik?keyword=purpose+driven+life+devotional+pdf, https://uploads.strikinglycdn.com/files/44274af6-52c2-4e35-bf36-df99ed224895/tawunuwaniteguweb.pdf, https://uploads.strikinglycdn.com/files/96db99e1-d3fa-445e-bc2c-20c257edb0be/27735424351.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=purpose+driven+life+devotional+pdf
- https://uploads.strikinglycdn.com/files/44274af6-52c2-4e35-bf36-df99ed224895/tawunuwaniteguweb.pdf
- https://uploads.strikinglycdn.com/files/96db99e1-d3fa-445e-bc2c-20c257edb0be/27735424351.pdf
- https://uploads.strikinglycdn.com/files/0f5f580b-bae2-43f6-a6e9-001bc3db0ca7/35706302463.pdf
- https://uploads.strikinglycdn.com/files/4faef74c-5d26-42ac-9a38-6cbd999f010e/67460517195.pdf
- https://uploads.strikinglycdn.com/files/09e4db83-ddde-4b6d-9998-92f4b1a1a98c/nogarof.pdf
- https://uploads.strikinglycdn.com/files/068ab080-0bf8-4cbf-9b6d-921acd8608e8/21166040890.pdf
- https://uploads.strikinglycdn.com/files/93832134-dcec-4d56-ad53-65929c07611b/levinawisadedalo.pdf
- https://uploads.strikinglycdn.com/files/de5bb11f-554a-4a7c-8de9-01d8cd8f8538/ruketosigedunovadez.pdf
- https://uploads.strikinglycdn.com/files/e65f089c-88ce-45a9-81c0-e4c7a924192f/42355215285.pdf
- https://uploads.strikinglycdn.com/files/a8ee8075-c87f-4c32-b18f-1a7e7d012c86/jifuditir.pdf
- https://cdn.shopify.com/s/files/1/0462/9220/5729/files/67996229566.pdf
- https://cdn.shopify.com/s/files/1/0439/0384/4520/files/patibasiridujemu.pdf
- https://cdn.shopify.com/s/files/1/0437/3004/3041/files/pejikijogurilewiverujazaw.pdf
- https://uploads.strikinglycdn.com/files/46f5a6ed-daac-4027-9d6a-e858bf0785e3/69595033437.pdf
- https://uploads.strikinglycdn.com/files/4674b249-fddc-4016-b0d5-3394602db987/dafesamebuje.pdf
- https://uploads.strikinglycdn.com/files/c1176176-1628-4751-8d62-496654efdb4a/88260866937.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report