MALICIOUS — fulefazisazogoranimenaf.pdf
MALICIOUS — fulefazisazogoranimenaf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (78/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
32249699b0b8fdbfcc99b2c279d7b50bb210e690f00452b8cc8f660c5c7cda97 - SHA-1:
a08ac0757d9087bdf173649d58fec0163e7b35aa - MD5:
2574e57920efbb9d330fdba800ee8e73 - ssdeep:
768:ggGzpDQyNWk4iLmPbuL866m0dmNzoykfUCMvKj20C0VvTSv:tGFMqnwjf8ZBkcpY20C0VTSv - TLSH:
T1D632BFF34157DC8CBA475B03ADBA18694146C78C7272A3A054D83AACC47C6FEAE50DB1 - Submitted as: fulefazisazogoranimenaf.pdf
- File type: pdf · Size: 43274 bytes
- Verdict: malicious (78/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 78/100 is the fusion of 5 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ggtraff.ru/strik?keyword=historical+thinking+and+other+unnatural+acts+pdf, https://uploads.strikinglycdn.com/files/81535853-59af-45c8-a868-d1b3762443c9/wikofase.pdf, https://uploads.strikinglycdn.com/files/4abc89a9-cc60-4580-92c9-121fc8e3e924/sexewakedun.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=historical+thinking+and+other+unnatural+acts+pdf
- https://uploads.strikinglycdn.com/files/81535853-59af-45c8-a868-d1b3762443c9/wikofase.pdf
- https://uploads.strikinglycdn.com/files/4abc89a9-cc60-4580-92c9-121fc8e3e924/sexewakedun.pdf
- https://uploads.strikinglycdn.com/files/e7211fb7-9335-4bed-b1f6-cb4c6f1055e9/59226303567.pdf
- https://uploads.strikinglycdn.com/files/2c8e8d66-290f-4167-ad34-fd98ffcfa60c/46286351828.pdf
- https://site-1036742.mozfiles.com/files/1036742/88171989628.pdf
- https://site-1036761.mozfiles.com/files/1036761/32102733443.pdf
- https://site-1036945.mozfiles.com/files/1036945/tazuroz.pdf
- https://site-1037829.mozfiles.com/files/1037829/54283468194.pdf
- https://site-1037891.mozfiles.com/files/1037891/89590405559.pdf
- https://site-1037073.mozfiles.com/files/1037073/fepefazogewokunaj.pdf
- https://site-1037010.mozfiles.com/files/1037010/83019173254.pdf
- https://site-1036840.mozfiles.com/files/1036840/pulegatumenazopiwofanade.pdf
- https://site-1036698.mozfiles.com/files/1036698/zanuxigewupevoj.pdf
- https://uploads.strikinglycdn.com/files/199ec09a-662a-40fe-808b-bc0110ec94f8/90476777187.pdf
- https://uploads.strikinglycdn.com/files/392924f0-1e75-4583-8358-37393240f8be/sosunev.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036742.mozfiles.com
- site-1036761.mozfiles.com
- site-1036945.mozfiles.com
- site-1037829.mozfiles.com
- site-1037891.mozfiles.com
- site-1037073.mozfiles.com
- site-1037010.mozfiles.com
- site-1036840.mozfiles.com
- site-1036698.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report