SUSPICIOUS — fatajovafuwofulu.pdf
SUSPICIOUS — fatajovafuwofulu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
54eacf466ea389b81f9f01901a1e96dc72f0a4aa9ec1a5c89dff7f4f681b01c3 - SHA-1:
c586334bba20ac7289ad73f01b08da268311d339 - MD5:
9ee331cae4e9015e2c05cd019d41a3ed - ssdeep:
1536:iGFlIOGeEa6X/5gQeG9hDu/PmgWVBBiyQxc9+JCW:bFlIy5fMNgWVniyVgR - TLSH:
T18E349EF351CBDD8C7B8AEB1769A514586086D74D3022976058C8BB3DC4BC2FE7E60A90 - Submitted as: fatajovafuwofulu.pdf
- File type: pdf · Size: 53778 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/80d1e051-7ba8-4c30-9c26-86415c0af708/realidades_2_capitulo_3a-1_answer_key.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffine.ru/wb?keyword=torrent%20premiere%20pro%202019%20crack, https://vunukufe.weebly.com/uploads/1/3/4/6/134640969/wulefajikelumu_wizexazagofuziw_wipabem_zegakijebufusu.pdf, https://xubafema.weebly.com/uploads/1/3/4/4/134447535/ladopuvagizirijudi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffine.ru/wb?keyword=torrent%20premiere%20pro%202019%20crack
- https://vunukufe.weebly.com/uploads/1/3/4/6/134640969/wulefajikelumu_wizexazagofuziw_wipabem_zegakijebufusu.pdf
- https://xubafema.weebly.com/uploads/1/3/4/4/134447535/ladopuvagizirijudi.pdf
- https://s3.amazonaws.com/gaxuremewuger/samsung_tv_remote_application_not_available.pdf
- https://vavuxajibibugu.weebly.com/uploads/1/3/4/4/134472661/pezad.pdf
- https://uploads.strikinglycdn.com/files/ee61fc72-0311-4bdf-9910-c7ffbec68fa9/24924518652.pdf
- https://uploads.strikinglycdn.com/files/71cc61ad-f247-4959-ae6a-ebad93c962c4/18336457598.pdf
- https://uploads.strikinglycdn.com/files/80d1e051-7ba8-4c30-9c26-86415c0af708/realidades_2_capitulo_3a-1_answer_key.pdf
- https://uploads.strikinglycdn.com/files/89a6d3b6-3cd8-441c-b65a-349ba570dca7/how_to_recover_my_yahoo_account_password.pdf
- https://uploads.strikinglycdn.com/files/0faf609e-82bd-4ab3-90b1-4bfea646abb7/bujeguvekeforodelokosafe.pdf
- https://s3.amazonaws.com/pazovugal/nys_conditional_release_date.pdf
- https://uploads.strikinglycdn.com/files/ec4c9b81-4107-462d-b894-04dbdd299457/70840893869.pdf
- https://uploads.strikinglycdn.com/files/25baf735-0062-47c2-8ddd-d6bdfa7fcde8/benagijo.pdf
- https://towimoni.weebly.com/uploads/1/3/4/3/134340956/dapupadurulisaf_zoxex_kowovokak.pdf
- https://uploads.strikinglycdn.com/files/1198942e-8e75-498b-9880-8c07b2df874a/teresa_giudice_instagram_pics.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffine.ru
- vunukufe.weebly.com
- xubafema.weebly.com
- s3.amazonaws.com
- vavuxajibibugu.weebly.com
- uploads.strikinglycdn.com
- towimoni.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report