SUSPICIOUS — fabad-naxira.pdf
SUSPICIOUS — fabad-naxira.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
159854d16426827bb4be8665fa45b678567304a1f3aaba201eab60543e91df7b - SHA-1:
b6326f52783cc412837f303c499d2d4f686ed50e - MD5:
3dc27a4b03caf567bc7256dcd50bd925 - ssdeep:
768:vgGzpDSpz4Y56PLPX4UUkqBhRgs3dEdA+w+TOUUK9c28VK7n+T79P6Ul3tLu91:YGFepzv4Nw+Sfsc2K0AcUl9U1 - TLSH:
T1CC328DF3549BDD8DB98AAB479DA711956099C3CC6136EB50148C3B7CE0BCABD7E00860 - Submitted as: fabad-naxira.pdf
- File type: pdf · Size: 46479 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=javafx%20exception%20in%20application%20start%20method, https://site-1043967.mozfiles.com/files/1043967/sowagejugixutozijujorur.pdf, https://site-1043175.mozfiles.com/files/1043175/mageta.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=javafx%20exception%20in%20application%20start%20method
- https://site-1043967.mozfiles.com/files/1043967/sowagejugixutozijujorur.pdf
- https://site-1043175.mozfiles.com/files/1043175/mageta.pdf
- https://site-1040602.mozfiles.com/files/1040602/famotezesuraxelodu.pdf
- https://site-1036833.mozfiles.com/files/1036833/defuwibokosetokusewipiv.pdf
- https://site-1036692.mozfiles.com/files/1036692/pekuso.pdf
- https://cdn.shopify.com/s/files/1/0501/4952/3621/files/kofomituwes.pdf
- https://cdn.shopify.com/s/files/1/0482/1811/2154/files/memetabomovaluberos.pdf
- https://cdn.shopify.com/s/files/1/0432/8567/6188/files/pastor_joseph_prince_wife.pdf
- https://cdn.shopify.com/s/files/1/0431/0476/4068/files/psp_rom_downloader_apk.pdf
- https://site-1048206.mozfiles.com/files/1048206/voxotiju.pdf
- https://site-1038788.mozfiles.com/files/1038788/vudoguvepidajekop.pdf
- https://cdn.shopify.com/s/files/1/0434/2631/6455/files/lafaviw.pdf
- https://cdn.shopify.com/s/files/1/0501/8786/2194/files/ayurvedic_garbh_sanskar_download.pdf
- https://cdn.shopify.com/s/files/1/0432/0896/6301/files/soap_box_derby_car_plans.pdf
- https://cdn.shopify.com/s/files/1/0431/1770/7413/files/15513878949.pdf
- https://cdn.shopify.com/s/files/1/0493/5440/8095/files/bovisuboloterolaxosaganev.pdf
- https://uploads.strikinglycdn.com/files/768c3a6d-f3ba-4db1-9775-0573fee2cf31/fozutopemipubafi.pdf
- https://uploads.strikinglycdn.com/files/0a722acc-7b77-4b96-9b55-8502b9d62973/nozodekegitinogog.pdf
- https://uploads.strikinglycdn.com/files/ca1220b3-3f9f-4e46-8419-4ebd7cc004f3/43782365737.pdf
- https://uploads.strikinglycdn.com/files/83e2036b-f8c1-4dad-b016-ad4102cc6868/tibasofavomero.pdf
- https://uploads.strikinglycdn.com/files/5970f845-954f-4e3a-8359-01deb091e8e1/96582484303.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f870ffb61007.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f87c1284930f.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f877925cefae.pdf
Embedded domains
- ggtraff.ru
- site-1043967.mozfiles.com
- site-1043175.mozfiles.com
- site-1040602.mozfiles.com
- site-1036833.mozfiles.com
- site-1036692.mozfiles.com
- cdn.shopify.com
- site-1048206.mozfiles.com
- site-1038788.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report