SUSPICIOUS — pubufibezunekita.pdf
SUSPICIOUS — pubufibezunekita.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a50c732bd57ca15469f294fa970b47777aaaa3bcd3b70499210447ba890057d1 - SHA-1:
fc089a16ce01620ff208de6b7863942727f0b048 - MD5:
53c92d1d5e342b9ff2bb6b17d7a12fad - ssdeep:
1536:9GFoe5WS75auhLbY8C2p6ExREyg5JEuE:AFoe5WS1aUbY8np6EHEyCJg - TLSH:
T181359DF39197DD0C6A8BDF13ADEB3158914ADB4C6131AAA40489366CC5BC7BD7F00A21 - Submitted as: pubufibezunekita.pdf
- File type: pdf · Size: 61275 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=cuento%20escrito%20en%20prosa%20corto, https://uploads.strikinglycdn.com/files/5f3acc5c-69fe-4ad1-b83f-ee47cf975e8b/jinedijajomurinusa.pdf, https://uploads.strikinglycdn.com/files/efee4436-6b72-45de-a69b-a364cd46f707/bopafuzakim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=cuento%20escrito%20en%20prosa%20corto
- https://uploads.strikinglycdn.com/files/5f3acc5c-69fe-4ad1-b83f-ee47cf975e8b/jinedijajomurinusa.pdf
- https://uploads.strikinglycdn.com/files/efee4436-6b72-45de-a69b-a364cd46f707/bopafuzakim.pdf
- https://uploads.strikinglycdn.com/files/968b1098-d2c1-4467-8dcb-4e3e3ff40bba/fopefutas.pdf
- https://site-1036850.mozfiles.com/files/1036850/bifanutisusukizutaxeg.pdf
- https://site-1038339.mozfiles.com/files/1038339/baledagavub.pdf
- https://site-1039553.mozfiles.com/files/1039553/77333228056.pdf
- https://site-1039279.mozfiles.com/files/1039279/vajixeparuzesid.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f87e337b44d8.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f8722dc83035.pdf
- https://cdn-cms.f-static.net/uploads/4366647/normal_5f8766fbef12f.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f874d4c07171.pdf
- https://cdn.shopify.com/s/files/1/0268/9279/6073/files/20373491597.pdf
- https://cdn.shopify.com/s/files/1/0497/9356/4833/files/80571749455.pdf
- https://cdn.shopify.com/s/files/1/0437/9970/7805/files/us_county_map.pdf
- https://cdn.shopify.com/s/files/1/0492/3057/7817/files/google_drive_maleficent_mistress_of_evil_full_movie.pdf
- https://site-1039331.mozfiles.com/files/1039331/povozevelen.pdf
- https://site-1037843.mozfiles.com/files/1037843/84848654815.pdf
- https://site-1039785.mozfiles.com/files/1039785/fupuxuxudokamajij.pdf
- https://site-1040350.mozfiles.com/files/1040350/78199522830.pdf
- https://site-1042987.mozfiles.com/files/1042987/bonfiglioli_act_401_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036850.mozfiles.com
- site-1038339.mozfiles.com
- site-1039553.mozfiles.com
- site-1039279.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1039331.mozfiles.com
- site-1037843.mozfiles.com
- site-1039785.mozfiles.com
- site-1040350.mozfiles.com
- site-1042987.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report