SUSPICIOUS — fevov.pdf
SUSPICIOUS — fevov.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1fb6bfd26bd6c0be75158a5bb33c8f65d9089180dde5ceff7eb79f2023fa8b4a - SHA-1:
15976d58bacbb280a3dd7f14279b42b5ad53d931 - MD5:
940e5e620a21296fa48429a4fc1dc2d2 - ssdeep:
768:RgGzpDEpfAGsQ7lfz6Kd5d5N+l4vMWWpG88hciCCYCO6yX6fAm8Zct3mo7Oz+:iGFYpfBS0WXDiC7tCfAmfWaOz+ - TLSH:
T17A32AEF750A3DC8D3A8AAB036DBF055D604ED78861739650548DB32CD0BCAEE3E50A46 - Submitted as: fevov.pdf
- File type: pdf · Size: 45661 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish!atmn
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=coding%20with%20confidence, https://uploads.strikinglycdn.com/files/d422216d-4ca5-4bb4-9c90-9f5216e9f2ab/goxagigodeforo.pdf, https://uploads.strikinglycdn.com/files/eb288809-0193-446b-b778-ea853087c693/pibonamezevop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=coding%20with%20confidence
- https://uploads.strikinglycdn.com/files/d422216d-4ca5-4bb4-9c90-9f5216e9f2ab/goxagigodeforo.pdf
- https://uploads.strikinglycdn.com/files/eb288809-0193-446b-b778-ea853087c693/pibonamezevop.pdf
- https://uploads.strikinglycdn.com/files/d0b0e705-f5ea-42a9-b74e-6d7587329e94/suvegovod.pdf
- https://uploads.strikinglycdn.com/files/49b1100e-f79e-45b2-8a3b-792003eee7f2/bob_woodward_fear_book.pdf
- https://uploads.strikinglycdn.com/files/872d31f6-b7bc-4581-a030-6c502fc2d2d6/74347370894.pdf
- https://uploads.strikinglycdn.com/files/eb39f893-e791-40d3-a925-6926c9110b4a/niremutinozupa.pdf
- https://uploads.strikinglycdn.com/files/0f1dfd14-8dc4-4df6-b22b-8fc2fb949098/5797161798.pdf
- https://cdn.shopify.com/s/files/1/0481/3393/1171/files/lakeside_arena_schedule.pdf
- https://cdn.shopify.com/s/files/1/0482/8122/3336/files/chick_fil_a_marketing_director_salary.pdf
- https://cdn.shopify.com/s/files/1/0433/4783/7083/files/5348246657.pdf
- https://cdn.shopify.com/s/files/1/0432/4435/5739/files/www.wapking.in_movies_video_songs.pdf
- https://cdn.shopify.com/s/files/1/0434/0822/8508/files/xobupakejepopinimakotin.pdf
- https://uploads.strikinglycdn.com/files/e17dd65d-092a-4fef-a2df-53996e452457/wokanibafazotokemidom.pdf
- https://uploads.strikinglycdn.com/files/6627960b-23f4-4dd0-b5a8-e666a81a0eba/xoxujamak.pdf
- https://uploads.strikinglycdn.com/files/34912e69-85bd-4dab-8d26-04203cbdc0ef/99235267785.pdf
- https://uploads.strikinglycdn.com/files/483e1f5c-f219-4a9c-b60b-0ee3a619ce80/dikupetexutusebixa.pdf
- https://cdn-cms.f-static.net/uploads/4372740/normal_5f89c0b14c3b7.pdf
- https://cdn-cms.f-static.net/uploads/4370987/normal_5f8b0bb7adbe1.pdf
- https://cdn-cms.f-static.net/uploads/4374976/normal_5f89d245eabf9.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f86f93d6f527.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report