SUSPICIOUS — fusoxosowitajutotofavetos.pdf
SUSPICIOUS — fusoxosowitajutotofavetos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
0b349c23825e9cc5c638b1c6eb2c5a89794c1585b21d6939b52897b922610c04 - SHA-1:
5b17839e4d7ea91d36fcbf85d915ad8c420f6cb7 - MD5:
79bbbc568fbd4ef044af56b3458a4dcb - ssdeep:
768:NgGzpD2QEWfnPN1QWDPvUwiVPpImItMfslKONrpbk+XFfoPnS7aCVW4kGm:uGFyb4/D07U2fsljg+XFga7agnkGm - TLSH:
T1BB33AEF39057ED8CBA8BBF07ADEA1058508BD74971269A6048487B6CC07C7FC7E21A50 - Submitted as: fusoxosowitajutotofavetos.pdf
- File type: pdf · Size: 50290 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=canine+chronic+hepatitis+pdf, https://site-1037163.mozfiles.com/files/1037163/36289413695.pdf, https://site-1036962.mozfiles.com/files/1036962/93489251058.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=canine+chronic+hepatitis+pdf
- https://site-1037163.mozfiles.com/files/1037163/36289413695.pdf
- https://site-1036962.mozfiles.com/files/1036962/93489251058.pdf
- https://site-1038442.mozfiles.com/files/1038442/lazasewonejagawasidoji.pdf
- https://site-1037061.mozfiles.com/files/1037061/81118738474.pdf
- https://site-1037224.mozfiles.com/files/1037224/zanarala.pdf
- https://site-1036956.mozfiles.com/files/1036956/lagogaj.pdf
- https://site-1036767.mozfiles.com/files/1036767/maxudolejotomomamomodir.pdf
- https://site-1037262.mozfiles.com/files/1037262/vusemadegonafamot.pdf
- https://uploads.strikinglycdn.com/files/fbda0052-82c2-47ed-95e4-43d5ff7a6b3a/28860883762.pdf
- https://uploads.strikinglycdn.com/files/c8c47dfc-36da-4ca5-ad5a-05d0eb220a46/34710186203.pdf
- https://uploads.strikinglycdn.com/files/d8a7c208-5857-4d2c-abb6-8fa817c7bd5d/diruseruza.pdf
- https://uploads.strikinglycdn.com/files/275863dc-938e-451a-a108-7b07b398e506/siluwegubaf.pdf
- https://uploads.strikinglycdn.com/files/6a762de1-f146-451d-8303-15958dc8b35d/jamonero.pdf
- https://uploads.strikinglycdn.com/files/fde30a83-2acb-4167-8be9-e10af9bce789/roteguzekevoxezelis.pdf
- https://uploads.strikinglycdn.com/files/d2cbb882-a1c8-4995-8d4b-31f7272980a8/sulofi.pdf
- https://uploads.strikinglycdn.com/files/e4e26a71-b47e-4f2b-8d2d-b8224c3e643e/nixilesinakidolo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1037163.mozfiles.com
- site-1036962.mozfiles.com
- site-1038442.mozfiles.com
- site-1037061.mozfiles.com
- site-1037224.mozfiles.com
- site-1036956.mozfiles.com
- site-1036767.mozfiles.com
- site-1037262.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report