SUSPICIOUS — fufonomoraligenilalima.pdf
SUSPICIOUS — fufonomoraligenilalima.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
700f9573bc4e4977285d9b50829c48d17a025638e4d30da8bc07e4626fca0efa - SHA-1:
0f29f9d326e973fa929a75cdaf89def5e30d7e69 - MD5:
c5ad4c409abdcce99245c89845a1955f - ssdeep:
768:xgGzpD6sjXaik357Cq686e6HrV0pIGV5WzlLxRFQ7Gst1I:CGFFrM5WqSe6Hx0pX5WzlFvEGst1I - TLSH:
T12D31AEF316A7DD8C7A8BAB036CF911A56145C74D2133A3641898773CC4BC6BE7E609A0 - Submitted as: fufonomoraligenilalima.pdf
- File type: pdf · Size: 42839 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=stanly+funeral+home+concord+nc, https://uploads.strikinglycdn.com/files/d5804edb-13dc-4bf5-bede-016d37b783cb/75274619675.pdf, https://uploads.strikinglycdn.com/files/ed720173-67f6-4ab2-8787-621ddf6dbd7a/jafixaxedumepazo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=stanly+funeral+home+concord+nc
- https://uploads.strikinglycdn.com/files/d5804edb-13dc-4bf5-bede-016d37b783cb/75274619675.pdf
- https://uploads.strikinglycdn.com/files/ed720173-67f6-4ab2-8787-621ddf6dbd7a/jafixaxedumepazo.pdf
- https://uploads.strikinglycdn.com/files/da3e82a3-4065-4711-ae89-3bc0bd7a6301/47426598470.pdf
- https://uploads.strikinglycdn.com/files/6b3c59f2-511b-48b9-a6cd-dafbe4feffa6/zaweleguzetifebid.pdf
- http://files.breesevere.com/uploads/1/3/0/7/130775682/zesavatujib_zijalavaton_modujozad.pdf
- http://radajiwoz.dianebattistello.com/uploads/1/3/1/8/131871479/luxidut.pdf
- http://files.stagcoffeecardiff.com/uploads/1/3/1/4/131437889/gologewi.pdf
- https://site-1038413.mozfiles.com/files/1038413/13831832029.pdf
- https://site-1044255.mozfiles.com/files/1044255/fevazorogoka.pdf
- https://site-1036646.mozfiles.com/files/1036646/75505481595.pdf
- https://site-1037026.mozfiles.com/files/1037026/59061722070.pdf
- https://site-1040388.mozfiles.com/files/1040388/12092133603.pdf
- https://cdn.shopify.com/s/files/1/0482/3095/7208/files/97_camaro_ss_wheels.pdf
- https://cdn.shopify.com/s/files/1/0500/5780/5984/files/61335653347.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.breesevere.com
- radajiwoz.dianebattistello.com
- files.stagcoffeecardiff.com
- site-1038413.mozfiles.com
- site-1044255.mozfiles.com
- site-1036646.mozfiles.com
- site-1037026.mozfiles.com
- site-1040388.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report