SUSPICIOUS — fuporefufulipebega.pdf
SUSPICIOUS — fuporefufulipebega.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
30f93366f8c45ea1106fe3285d48e18e08d5164faec972110cd388c506daf3a1 - SHA-1:
de5868bd85d8b88c8d43e13e862b9e749817464d - MD5:
e63b6e6c89fc178798a4a4a6b99e3ae8 - ssdeep:
768:BgGzpDjpjqAdlBYW+8L/dSgxhCaQ09Z6vqwifECzQhQmmCKi9SR7FpgOE24Z97/q:yGFvpjfPxhW09MvqwiX+QFCTkDE24ZOB - TLSH:
T181339EF354A3EC4CBB8B9F13ACA714A96589D388912397A0458C772CC4BC1BD7E90D61 - Submitted as: fuporefufulipebega.pdf
- File type: pdf · Size: 48549 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=renewable%20energy%20sources%20question%20bank%20with%20answers%20pdf, https://cdn-cms.f-static.net/uploads/4369794/normal_5f87d665d1fae.pdf, https://cdn-cms.f-static.net/uploads/4365607/normal_5f8703141a89b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=renewable%20energy%20sources%20question%20bank%20with%20answers%20pdf
- https://cdn-cms.f-static.net/uploads/4369794/normal_5f87d665d1fae.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f8703141a89b.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f87c9d4eaa56.pdf
- https://cdn-cms.f-static.net/uploads/4370062/normal_5f8807471bac3.pdf
- https://cdn-cms.f-static.net/uploads/4367947/normal_5f87630497067.pdf
- https://site-1045415.mozfiles.com/files/1045415/37231645569.pdf
- https://uploads.strikinglycdn.com/files/7a3bde57-1836-46b8-b7fe-a775be836490/jifinatazuvalupeselowela.pdf
- https://uploads.strikinglycdn.com/files/3b2ddaf5-3fa8-4d4f-a751-ccd5739748a8/26237064311.pdf
- https://uploads.strikinglycdn.com/files/7a53f495-e50a-44c0-bf40-4078a1ac1a8c/74242860992.pdf
- https://uploads.strikinglycdn.com/files/236fe28b-e5c8-421c-8257-b37a5ee758d5/wilatamakabej.pdf
- https://uploads.strikinglycdn.com/files/d88243c8-c375-48dc-9e9d-db241cdc34d5/33465833382.pdf
- https://site-1045404.mozfiles.com/files/1045404/lurunesazigekimemajos.pdf
- https://site-1036995.mozfiles.com/files/1036995/gupozavufarifudi.pdf
- https://site-1038827.mozfiles.com/files/1038827/ribegowas.pdf
- https://site-1043043.mozfiles.com/files/1043043/56610917996.pdf
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/7684366.pdf
- https://roninuvanajeg.weebly.com/uploads/1/3/1/3/131379749/wodatevobifawebaral.pdf
- https://sepenunaxob.weebly.com/uploads/1/3/0/7/130776074/pupedevos_lobeju.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/fubisi.pdf
- https://zoxaminajoge.weebly.com/uploads/1/3/1/6/131637873/9544597.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f8776dd15298.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f87fd579512a.pdf
- https://cdn-cms.f-static.net/uploads/4368777/normal_5f885400ba6ac.pdf
- https://cdn-cms.f-static.net/uploads/4368975/normal_5f87fd1a1b84c.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1045415.mozfiles.com
- uploads.strikinglycdn.com
- site-1045404.mozfiles.com
- site-1036995.mozfiles.com
- site-1038827.mozfiles.com
- site-1043043.mozfiles.com
- vixijusodu.weebly.com
- roninuvanajeg.weebly.com
- sepenunaxob.weebly.com
- dutitujazekap.weebly.com
- zoxaminajoge.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report