SUSPICIOUS — fewefolagivovajaborapid.pdf
SUSPICIOUS — fewefolagivovajaborapid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2cf66004fc226c76c1de1945b305f415a5b7e946829852ddf7599ec72f264344 - SHA-1:
2c52a3fe8928c4b7751f56a88c56b12c8ed634be - MD5:
1b6b5bad16d953253bab43cf0940f76b - ssdeep:
768:fgGzpDwZW1ePw0tK7ddFhOMWMj/gkTSlXbQtjLL8BoWhpNQVkSSKd6:oGF8qdlONtkTSl0tjLLAoWRQjSKd6 - TLSH:
T141339EF34197DC4CB9C6AB47BAA604A97146C78C702695B090CC3B7DC4BC2FD6E40AA1 - Submitted as: fewefolagivovajaborapid.pdf
- File type: pdf · Size: 48387 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=syarah+kitab+tauhid+pdf, https://uploads.strikinglycdn.com/files/46057872-e822-41d6-acbf-78ea5a03fdf2/fitis.pdf, https://uploads.strikinglycdn.com/files/e1d5a272-140c-49db-814a-f4f956595e58/bamoripe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=syarah+kitab+tauhid+pdf
- https://uploads.strikinglycdn.com/files/46057872-e822-41d6-acbf-78ea5a03fdf2/fitis.pdf
- https://uploads.strikinglycdn.com/files/e1d5a272-140c-49db-814a-f4f956595e58/bamoripe.pdf
- https://uploads.strikinglycdn.com/files/973ea858-716d-4fbb-865b-b6c84edcfa15/wagonefikabi.pdf
- https://uploads.strikinglycdn.com/files/a2c1fef2-b60f-4212-994a-882570c576bc/20108328137.pdf
- https://cdn.shopify.com/s/files/1/0427/6515/6508/files/80780934156.pdf
- https://site-1039999.mozfiles.com/files/1039999/38746388217.pdf
- https://site-1038653.mozfiles.com/files/1038653/53009200796.pdf
- https://site-1036799.mozfiles.com/files/1036799/73876970619.pdf
- https://site-1039693.mozfiles.com/files/1039693/sodikexusorofobozibijezol.pdf
- https://cdn.shopify.com/s/files/1/0437/1008/7317/files/73832749272.pdf
- https://cdn.shopify.com/s/files/1/0434/0681/9477/files/ap_psychology_chapter_14_social_psychology_test.pdf
- https://cdn.shopify.com/s/files/1/0499/2371/9336/files/economics_eoct_study_guide.pdf
- https://cdn.shopify.com/s/files/1/0440/0241/0654/files/wezekirokisuk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1039999.mozfiles.com
- site-1038653.mozfiles.com
- site-1036799.mozfiles.com
- site-1039693.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report