SUSPICIOUS — fiwatemifav.pdf
SUSPICIOUS — fiwatemifav.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
87527268f60e5928683a910d88131f47f5bd26e985b163fb443265d5d8b18381 - SHA-1:
6a65e70dd704dfd02235b563d4fe4b525b828b20 - MD5:
9a69c01cf2eb4775620747653b296001 - ssdeep:
768:rgGzpD1D27qxiKkBwOjLH+grx/RDK5l0i3m8Ry4HUnqffz4qe:UGFBCjBG5lR2BnIfXe - TLSH:
T177318DF740A7ED8C7A86AB43ADEB05655089C38DA232D77058D8773CD4BC5BD6E00821 - Submitted as: fiwatemifav.pdf
- File type: pdf · Size: 43200 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=ohsas+18001+manual+pdf, https://cdn.shopify.com/s/files/1/0266/9241/9757/files/43638818260.pdf, https://cdn.shopify.com/s/files/1/0484/2143/7608/files/las_cabezas_de_san_juan_puerto_rico.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=ohsas+18001+manual+pdf
- https://cdn.shopify.com/s/files/1/0266/9241/9757/files/43638818260.pdf
- https://cdn.shopify.com/s/files/1/0484/2143/7608/files/las_cabezas_de_san_juan_puerto_rico.pdf
- https://cdn.shopify.com/s/files/1/0480/4496/6047/files/45694304581.pdf
- https://cdn.shopify.com/s/files/1/0429/5009/9100/files/xezagetolatawalixo.pdf
- https://cdn.shopify.com/s/files/1/0433/8299/7141/files/new_naruto_games_2020.pdf
- https://uploads.strikinglycdn.com/files/483a0de6-f858-4cdb-b86e-730296393944/13712396443.pdf
- https://uploads.strikinglycdn.com/files/7449c0f3-04bd-4238-b3d0-5e5917e0d02a/rizojanuxanaxavomi.pdf
- https://uploads.strikinglycdn.com/files/3f5a9b76-5026-4551-933a-4f535ed131b3/44893900745.pdf
- https://uploads.strikinglycdn.com/files/f3482c87-f075-4c98-8017-daed32389cdb/1989346113.pdf
- https://uploads.strikinglycdn.com/files/034d4941-aa7a-4cfa-9044-f7d6c5b2c1c8/kitogakirotefilutila.pdf
- http://files.katyscarlett.com/uploads/1/3/1/4/131454916/eb22a.pdf
- http://wiweroz.kenchungkachun.com/uploads/1/3/2/6/132681394/nonenivinup.pdf
- http://files.katherinechanmusic.com/uploads/1/3/2/8/132816066/a330e19b7.pdf
- http://files.antoniabehan.com/uploads/1/3/0/7/130740084/8e7186e36e.pdf
- http://files.societyofctopticians.org/uploads/1/3/1/4/131407882/6400240.pdf
- https://site-1041486.mozfiles.com/files/1041486/duzevolefapa.pdf
- https://site-1036799.mozfiles.com/files/1036799/31279103942.pdf
- https://site-1039351.mozfiles.com/files/1039351/jimasuxokizapaburalomeme.pdf
- https://site-1036621.mozfiles.com/files/1036621/zazebuporefego.pdf
- https://site-1039226.mozfiles.com/files/1039226/ditebujamit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- files.katyscarlett.com
- wiweroz.kenchungkachun.com
- files.katherinechanmusic.com
- files.antoniabehan.com
- files.societyofctopticians.org
- site-1041486.mozfiles.com
- site-1036799.mozfiles.com
- site-1039351.mozfiles.com
- site-1036621.mozfiles.com
- site-1039226.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report