SUSPICIOUS — fufiwukivanizo.pdf
SUSPICIOUS — fufiwukivanizo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
1524f1925503036bcc8b8837f5ed36ebeec15aeff822ff15eb2177559d3a4ad1 - SHA-1:
d867c9b8181359f0701d5ac0a8c2cd0ad0e9e0db - MD5:
8e9528866867d0cc7621358811840629 - ssdeep:
768:egGzpDy3lQs/ETiCwm56pnZFlPZHTBt2lu9AUHYGwZqB:bGFe3m8BT2lEAUHr+qB - TLSH:
T1FE2F8CF34097EE4C7A87AB036EE514586489C78CA236A7A4458C7B5DC4BC1FDBE40C60 - Submitted as: fufiwukivanizo.pdf
- File type: pdf · Size: 35720 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=grade+6+daily+reading+comprehension+pdf, https://site-1036686.mozfiles.com/files/1036686/doxesibamajixoduriraj.pdf, https://site-1039307.mozfiles.com/files/1039307/82234934680.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=grade+6+daily+reading+comprehension+pdf
- https://site-1036686.mozfiles.com/files/1036686/doxesibamajixoduriraj.pdf
- https://site-1039307.mozfiles.com/files/1039307/82234934680.pdf
- https://site-1036764.mozfiles.com/files/1036764/1852096597.pdf
- https://site-1037055.mozfiles.com/files/1037055/82089826712.pdf
- https://site-1039895.mozfiles.com/files/1039895/wosalokenorikawesubu.pdf
- https://site-1037202.mozfiles.com/files/1037202/14357808551.pdf
- https://site-1037245.mozfiles.com/files/1037245/19849494893.pdf
- https://site-1039257.mozfiles.com/files/1039257/59468388105.pdf
- https://site-1037848.mozfiles.com/files/1037848/tekiposopabimetuj.pdf
- https://site-1039749.mozfiles.com/files/1039749/tatexotuzinosevemonevi.pdf
- https://cdn.shopify.com/s/files/1/0440/9065/4885/files/63667672785.pdf
- https://cdn.shopify.com/s/files/1/0483/4780/7895/files/98695195455.pdf
- https://cdn.shopify.com/s/files/1/0433/4354/4488/files/econometric_theory_and_methods_solutions_manual.pdf
- https://cdn.shopify.com/s/files/1/0484/2890/8701/files/what_to_take_to_a_candlelight_vigil.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036686.mozfiles.com
- site-1039307.mozfiles.com
- site-1036764.mozfiles.com
- site-1037055.mozfiles.com
- site-1039895.mozfiles.com
- site-1037202.mozfiles.com
- site-1037245.mozfiles.com
- site-1039257.mozfiles.com
- site-1037848.mozfiles.com
- site-1039749.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report