SUSPICIOUS — fipitifesit.pdf
SUSPICIOUS — fipitifesit.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
93fc6707f8dac6e69ef845919de3e8343bb4da8160e9c2b40a9c36f922d88668 - SHA-1:
ccf65b3760cf276a07ceeb2d4752dacf2081b132 - MD5:
1d20c5b7eef887e83c0bd95d39b64c97 - ssdeep:
768:TgGzpD4pQf+6T7zAT5Pf3UEcOsWvP6E9d12EUv2LC+mX:sGFUpYyfEPiDrMEUOLC+mX - TLSH:
T1B0327DF314A7ED4CBA87AB87ADAB15685049838C6223D750498C772DC5BCABD7F40860 - Submitted as: fipitifesit.pdf
- File type: pdf · Size: 43268 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=comment%20se%20conf%C3%A9sser%20pdf, https://site-1040251.mozfiles.com/files/1040251/jixoximove.pdf, https://site-1037074.mozfiles.com/files/1037074/sodabegizur.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=comment%20se%20conf%C3%A9sser%20pdf
- https://site-1040251.mozfiles.com/files/1040251/jixoximove.pdf
- https://site-1037074.mozfiles.com/files/1037074/sodabegizur.pdf
- https://site-1036917.mozfiles.com/files/1036917/4599840545.pdf
- https://site-1043698.mozfiles.com/files/1043698/convert_microsoft_image_document_to.pdf
- https://site-1042969.mozfiles.com/files/1042969/nalojaxepevet.pdf
- https://uploads.strikinglycdn.com/files/81ff6ecf-6db7-4415-a1ee-84a622263489/92302633807.pdf
- https://uploads.strikinglycdn.com/files/c8a3907e-25a9-4b8e-b2ce-aa7e3b88d4ef/19722952651.pdf
- https://uploads.strikinglycdn.com/files/36e609d3-bfe7-4b3d-9816-f99119fbb560/dimifubufatomu.pdf
- https://uploads.strikinglycdn.com/files/889e609d-69c2-4d1c-8670-ccb83f015af6/52224603782.pdf
- https://uploads.strikinglycdn.com/files/a073ace7-2ec5-48d6-876b-7eb2a4ae6911/xugul.pdf
- https://uploads.strikinglycdn.com/files/ee121340-a51e-4694-bc6a-fc77258186c2/lukorodibibu.pdf
- https://uploads.strikinglycdn.com/files/dd66e3a2-a0d5-42ba-a68b-cbdfb5a01bb7/71463954703.pdf
- https://uploads.strikinglycdn.com/files/ffe1a6ab-e332-4a03-bf6e-44768b111182/66055398935.pdf
- https://uploads.strikinglycdn.com/files/4442ec39-5ccd-4487-b0d3-1687dc12dc05/55952504179.pdf
- https://uploads.strikinglycdn.com/files/8a05e062-be25-43ce-9eef-fae572bcd625/15896468086.pdf
- https://cdn.shopify.com/s/files/1/0481/7013/9797/files/satim.pdf
- https://cdn.shopify.com/s/files/1/0464/8668/3800/files/36052352635.pdf
- https://cdn.shopify.com/s/files/1/0436/1220/9309/files/59504363923.pdf
- https://cdn.shopify.com/s/files/1/0501/1472/3990/files/offline_browser_pro_apk_6.1.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/6583597.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/3621861.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/b97e7.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/jinitorip-bolag.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/digokasawuj-jipamuputevuf.pdf
Embedded domains
- ggtraff.ru
- site-1040251.mozfiles.com
- site-1037074.mozfiles.com
- site-1036917.mozfiles.com
- site-1043698.mozfiles.com
- site-1042969.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- dirigesibujov.weebly.com
- vewutaniwem.weebly.com
- megadezatesaram.weebly.com
- gimejexoxixaza.weebly.com
- keniwuki.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report