SUSPICIOUS — rikegirexemavekopi.pdf
SUSPICIOUS — rikegirexemavekopi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
fdc0dab5748455fe1121b328363bfe5f416f36cf1e89dfb75f79856da57af11d - SHA-1:
7cdbced5b91c34b6d8d47ecdfa09d2a5a839fcfc - MD5:
d93720708a8c77ad3ed558a1db92d978 - ssdeep:
768:bgGzpDQ0Zzjl/o0s6YUDwSe/CBii+9VVnDKyoL0KesSrb/uU28KBFHR0L:kGFcKDBd+VDKyoLLxSHoHR0L - TLSH:
T1D231AEF36067ED4D36866F53AEA2105AA44EC38C3032A9B415C87B6DC8BC5FD6D50861 - Submitted as: rikegirexemavekopi.pdf
- File type: pdf · Size: 40385 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=webcric.com%20live%20cricket, https://cdn.shopify.com/s/files/1/0507/5501/0735/files/benefagajijub.pdf, https://cdn.shopify.com/s/files/1/0497/2360/5153/files/78408753685.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=webcric.com%20live%20cricket
- https://cdn.shopify.com/s/files/1/0507/5501/0735/files/benefagajijub.pdf
- https://cdn.shopify.com/s/files/1/0497/2360/5153/files/78408753685.pdf
- https://cdn.shopify.com/s/files/1/0486/3075/9582/files/damodokegixilabep.pdf
- https://s3.amazonaws.com/wupixufekijax/persona_3_guide.pdf
- https://cdn.shopify.com/s/files/1/0432/9567/0427/files/dokanujipegitebide.pdf
- https://s3.amazonaws.com/susopuzupure/bavapub.pdf
- https://cdn.shopify.com/s/files/1/0430/2602/2557/files/mamitugewaxewufiwuzol.pdf
- https://cdn.shopify.com/s/files/1/0503/7437/7629/files/89241856155.pdf
- https://s3.amazonaws.com/sugaguxagu/indian_cabinet_minister_in_hindi.pdf
- https://cdn.shopify.com/s/files/1/0498/7712/3227/files/68887030734.pdf
- https://cdn.shopify.com/s/files/1/0496/6934/1341/files/27449185842.pdf
- https://s3.amazonaws.com/gezejoputiwinu/47937991423.pdf
- https://cdn-cms.f-static.net/uploads/4413375/normal_5f9d09958ef2c.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- webcric.com
- cdn.shopify.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report