MALICIOUS — fefepuvape.pdf
MALICIOUS — fefepuvape.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (88/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
04fda36a6b4913db072a9584b66eeb0660f82a980633d5ac9ec210992089da8c - SHA-1:
bf8a9c2c1d881e2dd9cf30ffdc59f21f87bb9f71 - MD5:
b6a41d8b7425a1863f690b933c8a899c - ssdeep:
768:ZgGzpDEWiZXP7vL0ORu5NENdh1HQF2RYixlIy0t142:aGFwLkD8h1wvixiy0t142 - TLSH:
T1DB307DF31066EE4D7E8397937DA701866049C2887173E7A01888BB6DC8BC17DBF519A1 - Submitted as: fefepuvape.pdf
- File type: pdf · Size: 35755 bytes
- Verdict: malicious (88/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The malicious score of 88/100 is the fusion of 6 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ggtraff.ru/strik?keyword=convertir+de+pdf+a+word+gratis+online+en+espa%25C3%25B1ol, http://files.wilmingtonchristian.org/uploads/1/3/1/3/131382808/6923046.pdf, http://files.christcathedralfayetteville.org/uploads/1/3/1/0/131069863/gusafedok-pofeweromutiv-megowalesule-xonolewavowesu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=convertir+de+pdf+a+word+gratis+online+en+espa%25C3%25B1ol
- http://files.wilmingtonchristian.org/uploads/1/3/1/3/131382808/6923046.pdf
- http://files.christcathedralfayetteville.org/uploads/1/3/1/0/131069863/gusafedok-pofeweromutiv-megowalesule-xonolewavowesu.pdf
- http://jivipumoj.genefambrough.com/uploads/1/3/1/4/131453870/pololeziwaluma.pdf
- http://files.lastdaymedia.com/uploads/1/3/2/6/132681949/44c7de51e.pdf
- https://cdn.shopify.com/s/files/1/0428/7463/4403/files/after_effects_software_for_pc.pdf
- http://files.mamasjourneys.com.au/uploads/1/3/1/4/131452801/4f8b0974979bb.pdf
- http://gunape.camandmica.com/uploads/1/3/1/6/131637830/tikoligerelanenup.pdf
- http://gidokimi.esthermcohen.com/uploads/1/3/0/7/130739624/fivovekasozum-xumele-lisar-nozejederex.pdf
- http://vasoniw.countrysquireinn.com/uploads/1/3/0/9/130969497/6254605.pdf
- https://cdn.shopify.com/s/files/1/0437/4921/2311/files/79807769970.pdf
- https://cdn.shopify.com/s/files/1/0432/1706/0007/files/nightmare_before_christmas_corpse_bride_frankenweenie_connection.pdf
- https://cdn.shopify.com/s/files/1/0431/8366/9412/files/microsoft_outlook_for_windows_10.pdf
- https://cdn.shopify.com/s/files/1/0434/6052/6246/files/diablo_2no_cd.pdf
- https://cdn.shopify.com/s/files/1/0434/6265/6157/files/58371634749.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.wilmingtonchristian.org
- files.christcathedralfayetteville.org
- jivipumoj.genefambrough.com
- files.lastdaymedia.com
- cdn.shopify.com
- files.mamasjourneys.com.au
- gunape.camandmica.com
- gidokimi.esthermcohen.com
- vasoniw.countrysquireinn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report