SUSPICIOUS — tugutofanizijaw.pdf
SUSPICIOUS — tugutofanizijaw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
29487035c1765c9fb0fff33cee896be1056e7abffb8eb831d4632277cb892ca6 - SHA-1:
85f3ede0d40b4d01e988b23631aa20e47d7f682a - MD5:
8bf643316572318b33d654a0b1d8c571 - ssdeep:
768:tgGzpD4eDVDci6hugaDyTZd891n9bc7CCTzZHZIbdfUHTghcYU1zknMyGynN:OGFceTqg1n94FZIbNThczzknOynN - TLSH:
T14E348DF31097ED8C7A8BAB83A9B711996585C3C97122D38050C87A6DC4BCAFC7F01665 - Submitted as: tugutofanizijaw.pdf
- File type: pdf · Size: 52916 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=office%202007%20full%20espa%C3%B1ol%20%20%20activador, https://cdn.shopify.com/s/files/1/0483/8939/0487/files/fibonacci_sequence_python_iteration.pdf, https://cdn.shopify.com/s/files/1/0429/8991/2218/files/iphone_6_logic_board_buy.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=office%202007%20full%20espa%C3%B1ol%20%20%20activador
- https://cdn.shopify.com/s/files/1/0483/8939/0487/files/fibonacci_sequence_python_iteration.pdf
- https://cdn.shopify.com/s/files/1/0429/8991/2218/files/iphone_6_logic_board_buy.pdf
- https://cdn.shopify.com/s/files/1/0467/9837/3015/files/kisaku.pdf
- https://cdn.shopify.com/s/files/1/0435/9467/8435/files/strong_and_weak_acids_and_bases_chart.pdf
- https://cdn.shopify.com/s/files/1/0430/8716/7645/files/zosoduturubesid.pdf
- https://site-1038504.mozfiles.com/files/1038504/63968842509.pdf
- https://site-1039847.mozfiles.com/files/1039847/xuzemodokofave.pdf
- https://site-1042674.mozfiles.com/files/1042674/gowolawimolaf.pdf
- https://site-1039847.mozfiles.com/files/1039847/nibuda.pdf
- https://site-1043438.mozfiles.com/files/1043438/62347281415.pdf
- https://site-1041395.mozfiles.com/files/1041395/dogukanuraxixawobotakufeb.pdf
- https://site-1038898.mozfiles.com/files/1038898/31400003216.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f87622856f9b.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f87595d0894b.pdf
- https://cdn-cms.f-static.net/uploads/4368971/normal_5f88d72b901c3.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/faxenute.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/linurigaruxox.pdf
- https://fagisidide.weebly.com/uploads/1/3/2/6/132682833/8703842.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/3794757.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/xelabodiko.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1038504.mozfiles.com
- site-1039847.mozfiles.com
- site-1042674.mozfiles.com
- site-1043438.mozfiles.com
- site-1041395.mozfiles.com
- site-1038898.mozfiles.com
- cdn-cms.f-static.net
- vozunutav.weebly.com
- fijojonibiw.weebly.com
- fagisidide.weebly.com
- bedizegoresupa.weebly.com
- jezaxegare.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report