SUSPICIOUS — fazefunimarazamosimip.pdf
SUSPICIOUS — fazefunimarazamosimip.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
aca52086221173a797bc8704825d24aa2d20bdce078d73da01352d5ad41f4d05 - SHA-1:
76c86a86e199c81cd0d8ba62aba694a3407396ff - MD5:
244057ef958f1b6148d6b8171017e823 - ssdeep:
1536:ISGFXVR73z1udUfUYwdoH5ehnr8LO0oNF:ILFXVRP1HfUYwdM5eP1 - TLSH:
T16533BFF38093DC8C76C66B97ADF618696149C38CA022E7A494C87B6CC57C7FD1E90A50 - Submitted as: fazefunimarazamosimip.pdf
- File type: pdf · Size: 51855 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=weekly+calendar+pdf+2018, https://uploads.strikinglycdn.com/files/6dbc105b-6b39-462f-aa88-52b650f66fe6/54472286522.pdf, https://uploads.strikinglycdn.com/files/1f600adc-c046-4dfb-a280-c2bf2bc734f8/9564716465.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=weekly+calendar+pdf+2018
- https://uploads.strikinglycdn.com/files/6dbc105b-6b39-462f-aa88-52b650f66fe6/54472286522.pdf
- https://uploads.strikinglycdn.com/files/1f600adc-c046-4dfb-a280-c2bf2bc734f8/9564716465.pdf
- https://uploads.strikinglycdn.com/files/53d8901d-3f57-4cff-aaca-2a3f1fef2498/48122703114.pdf
- https://uploads.strikinglycdn.com/files/de1d6c2d-0889-47f2-9f0c-9450fc8edc4c/11013507903.pdf
- http://nomofivuz.treeremovalftlauderdale.com/uploads/1/3/0/8/130873848/weladizenabev-wisevar.pdf
- http://gubozital.comfortembroidery.com/uploads/1/3/2/7/132712615/8003764.pdf
- http://mukona.bayareaflightinstruction.com/uploads/1/3/0/9/130969690/zakadogamov.pdf
- https://cdn.shopify.com/s/files/1/0429/2050/9596/files/rebumilolevawaj.pdf
- https://cdn.shopify.com/s/files/1/0428/7994/2812/files/nugivexunigos.pdf
- https://cdn.shopify.com/s/files/1/0449/0297/3595/files/98909997501.pdf
- https://cdn.shopify.com/s/files/1/0433/5792/9621/files/79764510941.pdf
- https://cdn.shopify.com/s/files/1/0433/7994/9718/files/98957204530.pdf
- https://site-1037241.mozfiles.com/files/1037241/fiweba.pdf
- https://site-1037191.mozfiles.com/files/1037191/6137000507.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- nomofivuz.treeremovalftlauderdale.com
- gubozital.comfortembroidery.com
- mukona.bayareaflightinstruction.com
- cdn.shopify.com
- site-1037241.mozfiles.com
- site-1037191.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report