SUSPICIOUS — vizufapufikimi.pdf
SUSPICIOUS — vizufapufikimi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
1f7a567ce2ed58174a489c13356fdb0e814cb42ba3074a4f314d9da3514cf7e9 - SHA-1:
0adb360ee2223f5fb6ab3573fc2037ee280c27ac - MD5:
42ed0956bcadc00607f36113c96de38c - ssdeep:
1536:DGFQ7e5K2qq6etVq4sdjIeeXZfaoq0EJfDL:SFQ7e5K2q5tre1aoqvJff - TLSH:
T148338CF350A7EC8C7A8B6F035DAB1059654AD38D6036E7A044C87B2DC4BC9BC7E10A61 - Submitted as: vizufapufikimi.pdf
- File type: pdf · Size: 50057 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=harry%20potter%20spanking%20fanfic, https://uploads.strikinglycdn.com/files/e0fd1088-6571-48b2-89eb-ac94a732b899/90231999717.pdf, https://uploads.strikinglycdn.com/files/63c88721-a614-458c-b3b5-f435465fe5d1/dogutejo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=harry%20potter%20spanking%20fanfic
- https://uploads.strikinglycdn.com/files/e0fd1088-6571-48b2-89eb-ac94a732b899/90231999717.pdf
- https://uploads.strikinglycdn.com/files/63c88721-a614-458c-b3b5-f435465fe5d1/dogutejo.pdf
- https://uploads.strikinglycdn.com/files/84c38443-b3b1-4c0e-a0c6-89258a3520e9/wusokenari.pdf
- https://uploads.strikinglycdn.com/files/6a1f4f9a-4195-441a-b37d-4132810c72f5/zinulolesiziwi.pdf
- https://uploads.strikinglycdn.com/files/6b79fdfd-3bac-4357-a1f1-1922b1df2f7a/64037369566.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f874de8d76b2.pdf
- https://cdn-cms.f-static.net/uploads/4368970/normal_5f87ae079a1c5.pdf
- https://cdn-cms.f-static.net/uploads/4367947/normal_5f877a09a6834.pdf
- https://cdn-cms.f-static.net/uploads/4366654/normal_5f8735d0ce7cd.pdf
- https://cdn.shopify.com/s/files/1/0496/4696/0803/files/xepepopomudefakuxepala.pdf
- https://cdn.shopify.com/s/files/1/0485/3052/2267/files/setelasajetavofiwosarimog.pdf
- https://uploads.strikinglycdn.com/files/54aab559-1744-4e38-9207-209f99ab8ae0/16434109322.pdf
- https://uploads.strikinglycdn.com/files/b230144f-93c2-4b87-8b9a-78725901c282/watokow.pdf
- https://uploads.strikinglycdn.com/files/2f325df1-e131-4222-b1fb-5f8d9e83c21d/91159047659.pdf
- https://uploads.strikinglycdn.com/files/2bfd4171-cfb7-48f8-a6c9-51e6eb652678/1071267548.pdf
- https://site-1036858.mozfiles.com/files/1036858/dawudebofigiwoxesuxuvu.pdf
- https://site-1043033.mozfiles.com/files/1043033/gopabileg.pdf
- https://cdn-cms.f-static.net/uploads/4366647/normal_5f876e10a6ad9.pdf
- https://cdn-cms.f-static.net/uploads/4368468/normal_5f877b9c8c1da.pdf
- https://cdn-cms.f-static.net/uploads/4366305/normal_5f87c56ca04b5.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f877ae586ebe.pdf
- https://cdn-cms.f-static.net/uploads/4368735/normal_5f87a2ccecafc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1036858.mozfiles.com
- site-1043033.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report