SUSPICIOUS — fasanosokojajafe.pdf
SUSPICIOUS — fasanosokojajafe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
4cf9a4a4d7edd57b359cbcc87c1e95616738ebc2376e8f62376b099aa3be191f - SHA-1:
f1161334eabdff4cd47f5b6c051ccf17c5c8ea20 - MD5:
ef8e7973095774dedef3dc7d16987315 - ssdeep:
768:jgGzpD4qADjBEhy0oS1xWU5T/OZ6XosVt8ti8KT/Yk0n8TTHBJDKiFNa:cGFEqgS/KdsG0TQkHTTfKiFNa - TLSH:
T1A132AEF71497ED4C3E82E713ADE95004614AC68C6036E66489CC7B2ED47C2FDAF24A61 - Submitted as: fasanosokojajafe.pdf
- File type: pdf · Size: 45934 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=carl+fischer+music+submissions, https://cdn.shopify.com/s/files/1/0437/9217/1165/files/nixadawetezatefenowek.pdf, https://cdn.shopify.com/s/files/1/0431/7364/2389/files/sport_heads_football_cards.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=carl+fischer+music+submissions
- https://cdn.shopify.com/s/files/1/0437/9217/1165/files/nixadawetezatefenowek.pdf
- https://cdn.shopify.com/s/files/1/0431/7364/2389/files/sport_heads_football_cards.pdf
- https://cdn.shopify.com/s/files/1/0430/6845/7113/files/bezoforudiloveg.pdf
- https://cdn.shopify.com/s/files/1/0479/6068/6748/files/closure_property_of_addition_of_natural_numbers.pdf
- https://site-1039838.mozfiles.com/files/1039838/lurupufemofelis.pdf
- https://uploads.strikinglycdn.com/files/730e6d84-b7c9-4381-9273-d9dea2c21f45/damiles.pdf
- https://uploads.strikinglycdn.com/files/644e5861-7376-4b2a-ae1a-a0db6bb2c49e/93942935.pdf
- https://uploads.strikinglycdn.com/files/0a3cd3b0-e74d-43b4-9862-eeb6203b9ac7/lofozikamumud.pdf
- https://uploads.strikinglycdn.com/files/c0a196f7-87c8-429c-9f32-db985d13fa0b/geguduxaterarinez.pdf
- https://uploads.strikinglycdn.com/files/93109652-7e81-4a3d-8847-e3f02f942fe2/telububisojakaberowe.pdf
- https://uploads.strikinglycdn.com/files/3e825217-60c6-4d4a-849a-c02c68acf6bd/gekilerivixanewuxitufu.pdf
- https://uploads.strikinglycdn.com/files/2fca31b3-64f4-4b54-a32d-2b0c9da829c7/74399557254.pdf
- https://uploads.strikinglycdn.com/files/9097d339-2b20-4f2b-80bb-df2d63dbfc85/xamoguvikalezodixodasum.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1039838.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report