SUSPICIOUS — fallout_4_finch_farm.pdf
SUSPICIOUS — fallout_4_finch_farm.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
216f0130586b8572e784f62e6976e12c839f97d166757a676eae2ad182c9ff66 - SHA-1:
fd8559eae8e275f7212cfbb6ffdf0d911748f1f2 - MD5:
3237e093e1fefcfeba6d2624ed3ed875 - ssdeep:
768:lgGzpDkYc4FhScJ5NrhSkQfDBTObAM+1QEls72+zZ2UUTdkdpEiD:2GF4dSJLrhQfDB/DI2+zZ2VBUEiD - TLSH:
T16D329EF350A7ED4C7F86AB4399BB21A96189C78C613797A0458C772CC4BC6BD3E00661 - Submitted as: fallout_4_finch_farm.pdf
- File type: pdf · Size: 44297 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=fallout+4+finch+farm, https://uploads.strikinglycdn.com/files/14bca184-5b10-49a0-b722-d235f4fb4d06/fanukoninerezosabewuniluw.pdf, https://uploads.strikinglycdn.com/files/6b6e5b1f-ebcc-4ecf-87cf-273653a90226/sasesoj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=fallout+4+finch+farm
- https://uploads.strikinglycdn.com/files/14bca184-5b10-49a0-b722-d235f4fb4d06/fanukoninerezosabewuniluw.pdf
- https://uploads.strikinglycdn.com/files/6b6e5b1f-ebcc-4ecf-87cf-273653a90226/sasesoj.pdf
- https://uploads.strikinglycdn.com/files/c1917502-9cfd-480c-8c11-6ed0e226e286/mufakojebaxokoda.pdf
- https://uploads.strikinglycdn.com/files/756c5e4b-d75f-49b0-a3ee-70ed12e5d2e8/exteroreceptores_de_la_piel.pdf
- https://s3.amazonaws.com/jamokaroxoj/79393525181.pdf
- https://s3.amazonaws.com/felasorarabipis/josum.pdf
- https://s3.amazonaws.com/memul/kafofonovomogakadumijar.pdf
- https://s3.amazonaws.com/donake/jifiniwa.pdf
- https://cdn-cms.f-static.net/uploads/4376379/normal_5f908052bbd4c.pdf
- https://cdn-cms.f-static.net/uploads/4369173/normal_5f922a1127a18.pdf
- https://cdn-cms.f-static.net/uploads/4368249/normal_5f880e2ba3b7d.pdf
- https://cdn-cms.f-static.net/uploads/4374379/normal_5f8c572a2f823.pdf
- https://s3.amazonaws.com/zuxadol/pidato_bahaya_narkoba.pdf
- https://s3.amazonaws.com/lodazojamuva/burger_king_gutscheine_sterreich.pdf
- https://s3.amazonaws.com/zesotat/balanitis_en_nios_tratamiento.pdf
- https://s3.amazonaws.com/buxoparadazegu/mizumuzoludafabu.pdf
- https://uploads.strikinglycdn.com/files/3c53ef0b-1f92-4ff1-92d7-b90a82888372/18467299957.pdf
- https://uploads.strikinglycdn.com/files/8997ecd7-76a9-4208-9358-0cd114fbeeb1/65645347838.pdf
- https://uploads.strikinglycdn.com/files/82004b3d-f088-4492-bbb2-cec38ca68dd3/93498524984.pdf
- https://uploads.strikinglycdn.com/files/8573331a-3a79-4701-9d1c-5f22db9fa1a9/55884195669.pdf
- https://uploads.strikinglycdn.com/files/b49a8b06-d4aa-40de-ac13-620cf21f1cda/wepujinazosotutoz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report