SUSPICIOUS — faf657a0e.pdf
SUSPICIOUS — faf657a0e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
51d86226a864c23669209a168ad3966d8b7d7fc378505e0eb498a436766d9b8b - SHA-1:
0da48a30d809b5dbcb2335cfd932cac3ba9d3d3b - MD5:
8d4fd798bc64029a6500ede6ba99a696 - ssdeep:
768:HagGzpD+pTVVioDLYwHvxkfXAkOQj7LQccZLncNQVA6dEy9GqV7ZCaKlNeUhHnk8:nGFipBnqPt9j6ZTOQdEyhKreyHkOvv - TLSH:
T129337DF31097EC4C7A9E9B039EAB1299604AD789A137D790044C776CD17CAAD3F10662 - Submitted as: faf657a0e.pdf
- File type: pdf · Size: 49103 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=memorandum%20of%20understanding%20sample, https://site-1039356.mozfiles.com/files/1039356/74827349000.pdf, https://site-1043537.mozfiles.com/files/1043537/purapiw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=memorandum%20of%20understanding%20sample
- https://site-1039356.mozfiles.com/files/1039356/74827349000.pdf
- https://site-1043537.mozfiles.com/files/1043537/purapiw.pdf
- https://site-1042670.mozfiles.com/files/1042670/69445848192.pdf
- https://site-1043664.mozfiles.com/files/1043664/pivutajutisixe.pdf
- https://site-1043128.mozfiles.com/files/1043128/mobujegup.pdf
- https://site-1039815.mozfiles.com/files/1039815/xuzoxozusinirova.pdf
- https://site-1039235.mozfiles.com/files/1039235/tagiju.pdf
- https://site-1043257.mozfiles.com/files/1043257/unfortunately_contacts_has_stopped_android.pdf
- https://uploads.strikinglycdn.com/files/17e5a2b6-f692-4d17-bac7-a7822e77daa0/30623267589.pdf
- https://uploads.strikinglycdn.com/files/a02c1482-e425-4299-ae80-d02800512d92/nanowiluwabuzojal.pdf
- https://uploads.strikinglycdn.com/files/cb884390-22b4-476d-b8ec-b718e19ba4ab/11186831928.pdf
- https://uploads.strikinglycdn.com/files/3cf0917e-fadd-49d1-9258-fbe4b0be9382/24233080383.pdf
- https://uploads.strikinglycdn.com/files/7c5f9ab4-c79a-4d75-ab61-664e8dbfb62c/71243760913.pdf
- https://site-1038538.mozfiles.com/files/1038538/80854525514.pdf
- https://site-1040669.mozfiles.com/files/1040669/32314017359.pdf
- https://site-1042343.mozfiles.com/files/1042343/64987333024.pdf
- https://site-1037245.mozfiles.com/files/1037245/cuddalore_district_pincode_list.pdf
- https://site-1038693.mozfiles.com/files/1038693/22488579124.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/6431815.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/c56fe1350421a6.pdf
- https://roninuvanajeg.weebly.com/uploads/1/3/1/3/131379749/luvoviwof.pdf
- https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/5647392.pdf
- https://besavikeneg.weebly.com/uploads/1/3/2/8/132815808/9220672.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/tufus-gomeb-duziradorojagaf.pdf
Embedded domains
- cctraff.ru
- site-1039356.mozfiles.com
- site-1043537.mozfiles.com
- site-1042670.mozfiles.com
- site-1043664.mozfiles.com
- site-1043128.mozfiles.com
- site-1039815.mozfiles.com
- site-1039235.mozfiles.com
- site-1043257.mozfiles.com
- uploads.strikinglycdn.com
- site-1038538.mozfiles.com
- site-1040669.mozfiles.com
- site-1042343.mozfiles.com
- site-1037245.mozfiles.com
- site-1038693.mozfiles.com
- jakedekokobara.weebly.com
- dapujevubo.weebly.com
- roninuvanajeg.weebly.com
- wekubuzebebam.weebly.com
- besavikeneg.weebly.com
- rakamukomegu.weebly.com
- lagukekejase.weebly.com
- fagisidide.weebly.com
- wivupenoremew.weebly.com
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report