SUSPICIOUS — fajivowuropeguroga.pdf
SUSPICIOUS — fajivowuropeguroga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
af52845cecc186fadc46305ebd3d41ad16a80213c7a142985d64d9fc4d9ab25d - SHA-1:
474dfebe595a4d0ed32742c66f56698efa666b7b - MD5:
2745d73f9c01a308ea3e852d22859b64 - ssdeep:
768:sgGzpDfeeCfM+Z7+fW133IDKW9C/YDGbcNMMlutrLEOA1PTBgHs+oX:pGFDeHuWVYD/YXbcTlMEvPTBgHs+oX - TLSH:
T14E339DF36597DE0C7A87AB136EBB21192189C38C7136D7508898772CD47C6BDAE10930 - Submitted as: fajivowuropeguroga.pdf
- File type: pdf · Size: 49004 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=ejercicios%20de%20regla%20de%20tres%20simple%20inversa, https://site-1038943.mozfiles.com/files/1038943/56845076130.pdf, https://site-1042271.mozfiles.com/files/1042271/63076478838.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=ejercicios%20de%20regla%20de%20tres%20simple%20inversa
- https://site-1038943.mozfiles.com/files/1038943/56845076130.pdf
- https://site-1042271.mozfiles.com/files/1042271/63076478838.pdf
- https://site-1038387.mozfiles.com/files/1038387/dalirifejesowudatajow.pdf
- https://site-1042349.mozfiles.com/files/1042349/pepinikijiroliwivite.pdf
- https://site-1038932.mozfiles.com/files/1038932/pajumafaxemede.pdf
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f87a51cf091d.pdf
- https://uploads.strikinglycdn.com/files/be1e7503-ebf2-4edc-be3a-3261d430ce43/25706358937.pdf
- https://uploads.strikinglycdn.com/files/6a264d3e-95a1-4871-a30e-3aa8d1c75a62/vipikepemipavosawejut.pdf
- https://uploads.strikinglycdn.com/files/c5d5f4cd-6892-4cdb-87ea-f9dba330f469/madaxolanesogalijakifa.pdf
- https://uploads.strikinglycdn.com/files/a4bc3740-9c39-43b8-9235-60a73bf401c1/wulaligij.pdf
- https://uploads.strikinglycdn.com/files/11391349-55be-4361-ac0a-737faffa4ab5/47563545509.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f873aa2cc611.pdf
- https://cdn-cms.f-static.net/uploads/4369166/normal_5f87e66197ce2.pdf
- https://uploads.strikinglycdn.com/files/a313e3e1-38a4-4dc7-9a8e-86eaeb1106d1/lapozav.pdf
- https://uploads.strikinglycdn.com/files/e095d2bc-29cf-4ebf-96ca-d9fa3eba1ec8/72999767335.pdf
- https://uploads.strikinglycdn.com/files/7fb882ea-9d99-4b80-89fa-98f62f7f4c74/48269771913.pdf
- https://uploads.strikinglycdn.com/files/452e0f3a-a454-4e6d-9dbc-f603a0993d2f/zesobelojevi.pdf
- https://uploads.strikinglycdn.com/files/762c31da-3486-4552-91bb-cc45fbc98b70/zepesogijugivutewoje.pdf
- https://site-1038779.mozfiles.com/files/1038779/12006013606.pdf
- https://site-1043130.mozfiles.com/files/1043130/34917817605.pdf
- https://site-1040104.mozfiles.com/files/1040104/27623873998.pdf
- https://site-1037106.mozfiles.com/files/1037106/4769899543.pdf
- https://site-1038522.mozfiles.com/files/1038522/88989351839.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- site-1038943.mozfiles.com
- site-1042271.mozfiles.com
- site-1038387.mozfiles.com
- site-1042349.mozfiles.com
- site-1038932.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038779.mozfiles.com
- site-1043130.mozfiles.com
- site-1040104.mozfiles.com
- site-1037106.mozfiles.com
- site-1038522.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report