SUSPICIOUS — puxifekapazibanenelaxe.pdf
SUSPICIOUS — puxifekapazibanenelaxe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f1846b93ef45e8d3fbc54a422c34556b55f173763f043d1395b4b7fcdb738e13 - SHA-1:
629605dc833e4dbdd5b0f5fb7794a5a70b423adf - MD5:
c07ec33e29b55efc4d9e7cb3071f6f11 - ssdeep:
1536:HGFX5wRczpgR5Y3/c8rUdkAEEs5wB78/jgSCmn6:mFXagg38r2kBz5g78/jgSCl - TLSH:
T1BA35D0F39567ED4C7ACAAB536AE620598080D7889075D7A010C9BB3CC4F837CAE05D71 - Submitted as: puxifekapazibanenelaxe.pdf
- File type: pdf · Size: 63283 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=europe%2527s+climate+zones+and+vegetation, https://cdn.shopify.com/s/files/1/0438/4705/7568/files/a_man_with_a_plan_quote.pdf, https://cdn.shopify.com/s/files/1/0428/8158/1223/files/gta_san_andreas_apk_obb_1.08.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=europe%2527s+climate+zones+and+vegetation
- https://cdn.shopify.com/s/files/1/0438/4705/7568/files/a_man_with_a_plan_quote.pdf
- https://cdn.shopify.com/s/files/1/0428/2069/8268/files/depot_square_hardware.pdf
- https://cdn.shopify.com/s/files/1/0428/8158/1223/files/gta_san_andreas_apk_obb_1.08.pdf
- https://cdn.shopify.com/s/files/1/0462/7166/0189/files/kexatamorolu.pdf
- https://cdn.shopify.com/s/files/1/0482/9737/7956/files/paginas_para_ver_peliculas_gratis_en_espaol_repelis.pdf
- http://depim.jamesmhatch.com/uploads/1/3/0/7/130776321/2d42d3225e21.pdf
- http://files.surftripguru.com/uploads/1/3/1/4/131405958/2949303.pdf
- http://files.jerseyshorewellness.com/uploads/1/3/2/8/132815359/tifowovomuxoxuzofeme.pdf
- http://files.soyninasales.com/uploads/1/3/1/4/131482996/3587332.pdf
- https://site-1041614.mozfiles.com/files/1041614/fugaboxijeregorewemedim.pdf
- https://site-1041768.mozfiles.com/files/1041768/85439495119.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- depim.jamesmhatch.com
- files.surftripguru.com
- files.jerseyshorewellness.com
- files.soyninasales.com
- site-1041614.mozfiles.com
- site-1041768.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report