SUSPICIOUS — fiwax.pdf
SUSPICIOUS — fiwax.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
96f5f10424031c76e09d8e40871ab6aece8f9e32fd54c4358870acb04cf319ff - SHA-1:
83761962e4a9f8cc1eaa56c12c61bc5fdc027886 - MD5:
f25323f82a61ea6f536352ecc481d29e - ssdeep:
1536:4GFY9DesxahR2hlb/wlMv8PlxrcILxg0dOQGXR1W6Pa:VFY9Desy20K0txrHLxgMqRgJ - TLSH:
T1D937DFF3949BCD4C798B6F1329FA142CA545EB858239E360088CB73DC5BC3AD6E11A54 - Submitted as: fiwax.pdf
- File type: pdf · Size: 71956 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ea10949d-5749-4cc1-9f42-a4c27022f11b/55248637683.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=canada+immigration+form+pdf, https://site-1037903.mozfiles.com/files/1037903/26886592662.pdf, https://site-1037152.mozfiles.com/files/1037152/93046429473.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=canada+immigration+form+pdf
- https://site-1037903.mozfiles.com/files/1037903/26886592662.pdf
- https://site-1037152.mozfiles.com/files/1037152/93046429473.pdf
- https://site-1037279.mozfiles.com/files/1037279/17133401692.pdf
- https://site-1037125.mozfiles.com/files/1037125/85485683370.pdf
- https://site-1037169.mozfiles.com/files/1037169/jogalaxabanuv.pdf
- https://uploads.strikinglycdn.com/files/ea10949d-5749-4cc1-9f42-a4c27022f11b/55248637683.pdf
- https://uploads.strikinglycdn.com/files/ba819032-2167-42fd-b950-66cd621329bd/pemikitokowupap.pdf
- https://uploads.strikinglycdn.com/files/f21a3fae-dc42-4e0a-bbb9-778a66bcd8f4/tomidupamifenunavad.pdf
- https://uploads.strikinglycdn.com/files/8e8c38a5-59ed-445b-9e48-9f5c6ac35f9f/vanurukupugujad.pdf
- https://uploads.strikinglycdn.com/files/1cdd58ac-c346-4c3c-aa77-35834712ed3c/mawofupu.pdf
- https://site-1037141.mozfiles.com/files/1037141/lufasakopigonukogobidos.pdf
- https://site-1036830.mozfiles.com/files/1036830/jolamawadixo.pdf
- https://uploads.strikinglycdn.com/files/0799dd91-a239-4193-b903-9f65b9cfa45e/devuvexuxidiwupatipami.pdf
- https://uploads.strikinglycdn.com/files/036c8f58-350f-47bf-9e4e-457629e10071/fupaxelonopadewilokanuse.pdf
- https://uploads.strikinglycdn.com/files/35213ab7-0b17-45aa-97a3-29927a476077/tukivosisubejagesovalofa.pdf
- https://uploads.strikinglycdn.com/files/1f29133e-5216-4433-a948-6d4fb333cf32/22251144885.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037903.mozfiles.com
- site-1037152.mozfiles.com
- site-1037279.mozfiles.com
- site-1037125.mozfiles.com
- site-1037169.mozfiles.com
- uploads.strikinglycdn.com
- site-1037141.mozfiles.com
- site-1036830.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report