SUSPICIOUS — fimas.pdf
SUSPICIOUS — fimas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
59a727230f0870f74741be7b9f3638e5c6b9140d791b49f01c2ebcdb2cc021f6 - SHA-1:
a1427bbe45995d39df3a64eb68cfdb9232cede61 - MD5:
b0369bab253fdbdca70bc9f525c63b01 - ssdeep:
768:WgGzpDjpWXiv4VQFZtSJ/qO21M07hzCnzsPCaiutSmT3y+ESEfHdL47R+:DGF/pqaMwhzIzs3iutS97fh47R+ - TLSH:
T17D328CF7109BED4C79879F037DB626AAA589C7896137E750588C762CC8BC1BD2F10920 - Submitted as: fimas.pdf
- File type: pdf · Size: 45806 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=prelude%20in%20c%20major%20piano%20sheet%20pdf, https://uploads.strikinglycdn.com/files/7975ca17-7225-4225-9adf-d40ba6f0c2e5/5355090171.pdf, https://uploads.strikinglycdn.com/files/08eb85c5-67bd-4321-9647-07cf1c1f212b/legend_of_korra_free_streaming.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=prelude%20in%20c%20major%20piano%20sheet%20pdf
- https://uploads.strikinglycdn.com/files/7975ca17-7225-4225-9adf-d40ba6f0c2e5/5355090171.pdf
- https://uploads.strikinglycdn.com/files/08eb85c5-67bd-4321-9647-07cf1c1f212b/legend_of_korra_free_streaming.pdf
- https://uploads.strikinglycdn.com/files/12cf62aa-2bd8-42ee-995f-e11378f345d4/73001992113.pdf
- https://uploads.strikinglycdn.com/files/13d2d7be-e929-490b-b591-16e16b237c9d/23593178404.pdf
- https://uploads.strikinglycdn.com/files/455b6cc5-1948-4aed-8b0c-7962cf3539fe/towafulir.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f874922d31d6.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f8b10361b150.pdf
- https://cdn-cms.f-static.net/uploads/4393637/normal_5f9107c9ac67a.pdf
- https://cdn-cms.f-static.net/uploads/4375088/normal_5f8bb587c8016.pdf
- https://cdn-cms.f-static.net/uploads/4370275/normal_5f8902f479a70.pdf
- https://cdn-cms.f-static.net/uploads/4388280/normal_5f8fe7859406d.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f880a123cabe.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/3427a6b4f2903.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/cc5db455b7.pdf
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/makotu.pdf
- https://pasuliwipo.weebly.com/uploads/1/3/1/4/131452824/ralon_xusafadig.pdf
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/3b2b9375f04b146.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/ramolimisajo_wozos_rosokobaji_gatuwutujagas.pdf
- https://seririgikum.weebly.com/uploads/1/3/0/7/130739922/4c1794a6a4b7.pdf
- https://korebamo.weebly.com/uploads/1/3/0/7/130739662/sulevoda-dazuw-kavinitupoduf-nugonokoz.pdf
- https://s3.amazonaws.com/sugaguxagu/concept_of_human_development.pdf
- https://s3.amazonaws.com/zirojopemup/26766962999.pdf
- https://s3.amazonaws.com/xifabilejilab/tangled_i_see_the_light_piano.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- dutitujazekap.weebly.com
- pavowojavujide.weebly.com
- gemaxudemaxepeb.weebly.com
- pasuliwipo.weebly.com
- viweposedijul.weebly.com
- seririgikum.weebly.com
- korebamo.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report