SUSPICIOUS — fokajugadezela_lexefapi_tizov_fegarirug.pdf
SUSPICIOUS — fokajugadezela_lexefapi_tizov_fegarirug.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
4947c0895242334acfcb82c24d1c43a0d3542f8ba9ddc0423b99a9a9e5858127 - SHA-1:
4f2681db6d2926d8b6b7c0a63f58ea6e8bc5fd04 - MD5:
7daf8360c2ba93d0f0da8959d0223920 - ssdeep:
768:ngGzpDmpD0vqbaiwrLPEMalYGSc/WoqEfccoOfgK:gGFipEPOlYGS5EfFoOfgK - TLSH:
T110314BF310A7ED4CBA8B9F83ADAB15A9518ED3897136A7904488772DC47C5BC7F00960 - Submitted as: fokajugadezela_lexefapi_tizov_fegarirug.pdf
- File type: pdf · Size: 39443 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=geli%C5%9Fim%20psikolojisi%20konu%20anlat%C4%B1m%C4%B1%20pe, https://uploads.strikinglycdn.com/files/50e9dd10-83db-4dd4-b07a-ac62ad26412f/vigev.pdf, https://uploads.strikinglycdn.com/files/61d46215-ab64-4769-beb0-179534d31c26/soxigubolefasalotabiv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=geli%C5%9Fim%20psikolojisi%20konu%20anlat%C4%B1m%C4%B1%20pe
- https://uploads.strikinglycdn.com/files/50e9dd10-83db-4dd4-b07a-ac62ad26412f/vigev.pdf
- https://uploads.strikinglycdn.com/files/61d46215-ab64-4769-beb0-179534d31c26/soxigubolefasalotabiv.pdf
- https://uploads.strikinglycdn.com/files/c82af263-5353-41c5-9527-440f0e997695/83059540347.pdf
- https://uploads.strikinglycdn.com/files/11821d96-90e8-47be-8ddb-07dc93a73d18/96004967622.pdf
- https://site-1040597.mozfiles.com/files/1040597/42265574428.pdf
- https://site-1039864.mozfiles.com/files/1039864/serezumoxazivofeg.pdf
- https://site-1044024.mozfiles.com/files/1044024/6703683019.pdf
- https://site-1041291.mozfiles.com/files/1041291/14591792596.pdf
- https://site-1040794.mozfiles.com/files/1040794/94344370750.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/b919b1ed8f.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/dowixipadutume.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/duwivif.pdf
- https://mivosubewo.weebly.com/uploads/1/3/1/4/131407796/nurofig_teburovuxi_finona.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/939e82361.pdf
- https://site-1041852.mozfiles.com/files/1041852/xezolapejuzobonefa.pdf
- https://site-1043618.mozfiles.com/files/1043618/giwasarefefitupapapobu.pdf
- https://site-1044473.mozfiles.com/files/1044473/9201731900.pdf
- https://site-1037842.mozfiles.com/files/1037842/zalobuni.pdf
- https://site-1042981.mozfiles.com/files/1042981/38954078794.pdf
- https://uploads.strikinglycdn.com/files/f58b572a-dedb-40e9-af83-60bb2da2bb07/74047747571.pdf
- https://uploads.strikinglycdn.com/files/edff701a-79e1-467f-81c9-40df8424de51/kepefiki.pdf
- https://uploads.strikinglycdn.com/files/1123f54d-6153-470a-a1b8-7131b3679a17/91264947796.pdf
- https://uploads.strikinglycdn.com/files/17e2341b-0cc4-4cf0-b692-119a90ba1d6d/66323865919.pdf
- https://uploads.strikinglycdn.com/files/65ce711d-3c85-4987-a47a-bc452633c5f9/85297385832.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1040597.mozfiles.com
- site-1039864.mozfiles.com
- site-1044024.mozfiles.com
- site-1041291.mozfiles.com
- site-1040794.mozfiles.com
- zoxuzuxebexot.weebly.com
- nobinetezo.weebly.com
- genigudepa.weebly.com
- mivosubewo.weebly.com
- pumowurunumig.weebly.com
- site-1041852.mozfiles.com
- site-1043618.mozfiles.com
- site-1044473.mozfiles.com
- site-1037842.mozfiles.com
- site-1042981.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report