SUSPICIOUS — fa105f.pdf
SUSPICIOUS — fa105f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3f95fc5e543e07a628fa67be07cfe066a328ae1d58da9ea36d457481cfde2cee - SHA-1:
edaa8076454145ec16a48ecdfa722ceecafc56ed - MD5:
ed1f2cbb1491db32c8a96c843cf982ab - ssdeep:
768:XgGzpDYpI3VTtTUO3vHfRgWmf5tpmIIcWl3S+0goZ3QPKS:wGF8pJ0RSpmIIcWi+0gopQPKS - TLSH:
T1D3317EF310A7ED4C7A8B5F07AEE71158908AD78C6137E7A054882A2DD4BC6FC7E00965 - Submitted as: fa105f.pdf
- File type: pdf · Size: 39945 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=kehlani%20mp3%20download%20good%20life, https://site-1042770.mozfiles.com/files/1042770/25503584870.pdf, https://site-1036973.mozfiles.com/files/1036973/82955807995.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=kehlani%20mp3%20download%20good%20life
- https://site-1042770.mozfiles.com/files/1042770/25503584870.pdf
- https://site-1036973.mozfiles.com/files/1036973/82955807995.pdf
- https://site-1044018.mozfiles.com/files/1044018/91221580003.pdf
- https://site-1036735.mozfiles.com/files/1036735/45876926901.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f873b3082c32.pdf
- https://cdn-cms.f-static.net/uploads/4366385/normal_5f870dd95ee50.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f874679f3724.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f872b44984b4.pdf
- https://site-1039438.mozfiles.com/files/1039438/winetun.pdf
- https://site-1044064.mozfiles.com/files/1044064/13611044391.pdf
- https://site-1040506.mozfiles.com/files/1040506/wonuwoxolobunifegoburog.pdf
- https://site-1038605.mozfiles.com/files/1038605/zaneziziroruvudakixakev.pdf
- https://uploads.strikinglycdn.com/files/6e4f82ce-1786-4abb-8a33-1ee859063123/soremujasarawuvomasomo.pdf
- https://uploads.strikinglycdn.com/files/ebb2024f-abc6-4f4d-87da-b6557c87800c/62275547586.pdf
- https://uploads.strikinglycdn.com/files/b5b5e4b4-e63e-4aee-80a5-e8bb8cc2aff5/jivasozid.pdf
- https://uploads.strikinglycdn.com/files/be49f025-4ea3-478e-890f-0baac9157932/vewuzer.pdf
- https://uploads.strikinglycdn.com/files/a3f197f4-158c-4b3a-a32b-b029a1f8084a/90346386204.pdf
- https://uploads.strikinglycdn.com/files/f6ec5596-277d-41b6-9b0a-235f7abbd432/tuvujuwik.pdf
- https://uploads.strikinglycdn.com/files/cdb8efa8-45e9-410d-ba4f-c311904cdddb/38305809443.pdf
- https://uploads.strikinglycdn.com/files/bce6fc6d-0c03-4a17-8596-d0acef0fc944/tawemizalinokuzafofip.pdf
- https://site-1037160.mozfiles.com/files/1037160/karasitewa.pdf
- https://site-1043395.mozfiles.com/files/1043395/sefaro.pdf
- https://site-1042498.mozfiles.com/files/1042498/zulilegopozepanulomevelub.pdf
- https://site-1037893.mozfiles.com/files/1037893/63641852909.pdf
Embedded domains
- gettraff.ru
- site-1042770.mozfiles.com
- site-1036973.mozfiles.com
- site-1044018.mozfiles.com
- site-1036735.mozfiles.com
- cdn-cms.f-static.net
- site-1039438.mozfiles.com
- site-1044064.mozfiles.com
- site-1040506.mozfiles.com
- site-1038605.mozfiles.com
- uploads.strikinglycdn.com
- site-1037160.mozfiles.com
- site-1043395.mozfiles.com
- site-1042498.mozfiles.com
- site-1037893.mozfiles.com
- site-1043650.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report