SUSPICIOUS — fafufatasavo.pdf
SUSPICIOUS — fafufatasavo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
55671fd0ede291c49e2705f5f5cfe3cae428837fde02e83d5c228b53da55cec7 - SHA-1:
8303ee9c7ad5139f95d33bfeccb1077836adfaa1 - MD5:
ea6f715aa4fd1c74eb1c8af1cbe311af - ssdeep:
1536:OGF3pWbekVfnMqRh9DAIgDl/7BWgW11IjFB9:3F3pDkVfMqx+DNwgW11IjN - TLSH:
T1AA339EE350A7EC8C7B8B6B039EAB115C614ED38D6176876015887B6CC4BCAFD7E40A50 - Submitted as: fafufatasavo.pdf
- File type: pdf · Size: 50543 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=algoritmo%20de%20bresenham, https://site-1043458.mozfiles.com/files/1043458/folorolufegupidoteda.pdf, https://site-1037846.mozfiles.com/files/1037846/29920532690.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=algoritmo%20de%20bresenham
- https://site-1043458.mozfiles.com/files/1043458/folorolufegupidoteda.pdf
- https://site-1037846.mozfiles.com/files/1037846/29920532690.pdf
- https://site-1037922.mozfiles.com/files/1037922/16859361686.pdf
- https://site-1042879.mozfiles.com/files/1042879/riruzutapegivi.pdf
- https://site-1040600.mozfiles.com/files/1040600/goxovoxame.pdf
- https://uploads.strikinglycdn.com/files/8454b866-6a99-47c8-be81-7d766f5a81e9/banal.pdf
- https://cdn.shopify.com/s/files/1/0435/1436/4059/files/carhartt_made_in_usa_pants.pdf
- https://cdn.shopify.com/s/files/1/0491/8709/4694/files/vibe_4_in_1_universal_remote_manual.pdf
- https://cdn.shopify.com/s/files/1/0482/8233/7444/files/eve_ecm_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/3325/8915/files/2472379049.pdf
- https://cdn.shopify.com/s/files/1/0433/0523/8692/files/radio_shack_remote_15_302_code_list.pdf
- https://uploads.strikinglycdn.com/files/4e192ac6-b62b-44ce-8b54-e7f43f47b1c5/jaborapov.pdf
- https://uploads.strikinglycdn.com/files/ae5a1fe4-2f89-4ebe-aa1e-bcac5f45d006/rudezajakalujaj.pdf
- https://uploads.strikinglycdn.com/files/c5002f79-7532-4ab8-8675-b7bdf59ac713/48534603023.pdf
- https://uploads.strikinglycdn.com/files/4a5d5fe7-5d3f-4440-9215-eb5e42ee342e/gajojubuwasolejutez.pdf
- https://dedotomonifagax.weebly.com/uploads/1/3/1/6/131606429/rejajofejaroxokomido.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/tigosorivibisakoxu.pdf
- https://duxixujojive.weebly.com/uploads/1/3/0/7/130739103/6c26f1410aadb18.pdf
- https://nasinapalu.weebly.com/uploads/1/3/0/7/130739684/0e54a.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/porukofosu.pdf
- https://uploads.strikinglycdn.com/files/02e1aae0-12b8-4f4d-854c-9e958358e79c/64756920027.pdf
- https://uploads.strikinglycdn.com/files/02525821-0e91-4117-9329-300060664d76/kiguliro.pdf
- https://uploads.strikinglycdn.com/files/5cd4b1e0-7a50-4529-80b7-4cb56deffb04/99832907135.pdf
- https://uploads.strikinglycdn.com/files/9c0262ed-dd5e-4b55-a82f-2cb317a14afc/vanogidamudij.pdf
Embedded domains
- gettraff.ru
- site-1043458.mozfiles.com
- site-1037846.mozfiles.com
- site-1037922.mozfiles.com
- site-1042879.mozfiles.com
- site-1040600.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- dedotomonifagax.weebly.com
- jemiwuwavaza.weebly.com
- duxixujojive.weebly.com
- nasinapalu.weebly.com
- dimaxafazeza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report