SUSPICIOUS — fabij.pdf
SUSPICIOUS — fabij.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
71632001b9d2a531df113415fa80ac5c7c33b02d9f42a3f4e8a5f54097b488b6 - SHA-1:
a58580fe7b8a313b66f989bb0cb56ec87bdd4766 - MD5:
e73662a5e80565534c431bef3a3daf7b - ssdeep:
768:LgGzpDLvkGXh3Jb9utaeTrnyc+7pEh8lcZA5OsXjshpcNfaoSXRIq:0GFfLXD8XJIpFcK5OyjshpcgoSXRIq - TLSH:
T1F3318EF35093ED4C368BAF079EF714599449C68E213297A058C83B3DC4BC6BEAE11961 - Submitted as: fabij.pdf
- File type: pdf · Size: 42754 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffking.ru/wb?keyword=download%20mixcraft%208%20free%20full%20version, https://uploads.strikinglycdn.com/files/5a5df40b-3065-4192-8210-d0bfc54605e1/mowaj.pdf, https://uploads.strikinglycdn.com/files/1e763d50-05ea-4807-b96a-5a8f3140e5ee/nedipiwaxutilidepebuxetew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/wb?keyword=download%20mixcraft%208%20free%20full%20version
- https://s3.amazonaws.com/nawosineromigi/32733703102.pdf
- https://uploads.strikinglycdn.com/files/5a5df40b-3065-4192-8210-d0bfc54605e1/mowaj.pdf
- https://uploads.strikinglycdn.com/files/1e763d50-05ea-4807-b96a-5a8f3140e5ee/nedipiwaxutilidepebuxetew.pdf
- https://uploads.strikinglycdn.com/files/e9e25b00-f840-414a-a3b3-08a7b236f0b2/fesitajuzufupo.pdf
- https://uploads.strikinglycdn.com/files/27aeb933-cfdf-43ff-8573-c72fb926926a/98764084095.pdf
- https://s3.amazonaws.com/sowewazulejewi/jubasikuti.pdf
- https://uploads.strikinglycdn.com/files/9ef670c0-60a0-4775-b010-5aba7ec9938a/63800428150.pdf
- https://tidemipevu.weebly.com/uploads/1/3/0/7/130740592/bukuzopuzir-mikuxerojaweta-dapudokurogova-kowalime.pdf
- https://s3.amazonaws.com/henghuili-files/94088459266.pdf
- https://uploads.strikinglycdn.com/files/1af10c32-aa3f-440b-a2f2-40e011c1200e/zuvixekinibisijewitavi.pdf
- https://s3.amazonaws.com/jajoxulabojaso/channel_master_cm-3020_advantage_100_antenna.pdf
- https://s3.amazonaws.com/sinamozagemoger/19138761570.pdf
- https://s3.amazonaws.com/temujonuwu/yeoman_of_the_guard_score.pdf
- https://uploads.strikinglycdn.com/files/528fb094-d213-4abd-a7b4-eeda0fa8c91c/bibuwede.pdf
- https://uploads.strikinglycdn.com/files/90f533ea-3167-4df5-a2ea-df88ac615411/creative_color_wheel_lesson_plan.pdf
- https://uploads.strikinglycdn.com/files/13e813d6-c5b9-4f33-8aa3-a468432760bc/blaine_county_sheriff_s_office_gta.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- tidemipevu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report