SUSPICIOUS — fivesunulizezonofe.pdf
SUSPICIOUS — fivesunulizezonofe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a0269d7942129fa8dcbe80205a34200701dd67a7cbe98cc3c3eae2aaf2333029 - SHA-1:
cdfa6e19f650ed37c8851a1f005674a9f49374f7 - MD5:
fc5725a43aea719035f6ba3f19d92c62 - ssdeep:
1536:NGFRNQ/9woqZkviHqreNzylpml8qWhXhPk:QFR89woqZFqresmeJN6 - TLSH:
T1CC33BFFB50E7ED4C3A47AB03AEB71158818AC2896137E7B444C9763DC5785BDBE00852 - Submitted as: fivesunulizezonofe.pdf
- File type: pdf · Size: 51849 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=prince+records+price+guide, https://uploads.strikinglycdn.com/files/edb0d6cc-3707-459d-ad57-1170e85eff3c/jutujiwajinijon.pdf, https://uploads.strikinglycdn.com/files/7cd9112d-0539-46a8-829d-ab5c202ee638/kisanarasolitigesev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=prince+records+price+guide
- https://uploads.strikinglycdn.com/files/edb0d6cc-3707-459d-ad57-1170e85eff3c/jutujiwajinijon.pdf
- https://uploads.strikinglycdn.com/files/7cd9112d-0539-46a8-829d-ab5c202ee638/kisanarasolitigesev.pdf
- https://uploads.strikinglycdn.com/files/3bab80ea-cf50-4447-aeaf-cd1537108a2c/dufajazovikuxe.pdf
- https://uploads.strikinglycdn.com/files/079845c5-60a3-4f86-8aca-dd6af5b2d3f6/zezoxomawagejinidotek.pdf
- https://uploads.strikinglycdn.com/files/c47a461f-da38-49e7-99b2-a6b435b9db48/52176973945.pdf
- https://site-1048226.mozfiles.com/files/1048226/29352534660.pdf
- https://site-1037228.mozfiles.com/files/1037228/tokaxipebaz.pdf
- https://site-1039329.mozfiles.com/files/1039329/wozunadamitewobus.pdf
- https://site-1039720.mozfiles.com/files/1039720/36642921709.pdf
- https://site-1037010.mozfiles.com/files/1037010/17239628171.pdf
- https://site-1048260.mozfiles.com/files/1048260/sipuxojireforedig.pdf
- http://files.carriedi.com/uploads/1/3/1/4/131438501/9d8a9ad76445d.pdf
- http://tubolel.joanletourneau.com/uploads/1/3/0/9/130969723/feleroludopemag.pdf
- http://funozaxew.inhcc.net/uploads/1/3/1/4/131438819/kedipudi.pdf
- http://files.globalpetport.com/uploads/1/3/1/8/131856176/kedavaregibomezofa.pdf
- http://files.dangerday.com/uploads/1/3/1/3/131383247/tavefobefuridad-kenavaxo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1048226.mozfiles.com
- site-1037228.mozfiles.com
- site-1039329.mozfiles.com
- site-1039720.mozfiles.com
- site-1037010.mozfiles.com
- site-1048260.mozfiles.com
- files.carriedi.com
- tubolel.joanletourneau.com
- funozaxew.inhcc.net
- files.globalpetport.com
- files.dangerday.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report