SUSPICIOUS — fatifugozuzopuwatulaxajet.pdf
SUSPICIOUS — fatifugozuzopuwatulaxajet.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b1a8dad745636a9d06e3240a83d6c2d64b268ded5ae8d5b85a3eb4cecff2dc49 - SHA-1:
3eb9697df14524eb6b26a8c6e9b1813180768fb7 - MD5:
04ce3a3c273b9f1228472563b619c192 - ssdeep:
768:mgGzpDsXxee641TIFnR64f20tIHYh97rxmDwZlfJkqT:zGFoXyf20tkS9IDwZlfKqT - TLSH:
T12B308EF35097DE8C7E8F6B43AE671098504ACB887126A76049C9762CC97C5FD7F00661 - Submitted as: fatifugozuzopuwatulaxajet.pdf
- File type: pdf · Size: 38920 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=uniforme+adoratrices+logro%25C3%25B1o, https://cdn.shopify.com/s/files/1/0431/2704/6298/files/60_seconds_and_youre_hired_audiobook.pdf, https://cdn.shopify.com/s/files/1/0482/5366/5442/files/16593566267.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=uniforme+adoratrices+logro%25C3%25B1o
- https://cdn.shopify.com/s/files/1/0431/2704/6298/files/60_seconds_and_youre_hired_audiobook.pdf
- https://cdn.shopify.com/s/files/1/0482/5366/5442/files/16593566267.pdf
- https://cdn.shopify.com/s/files/1/0480/0420/2647/files/46646679162.pdf
- https://cdn.shopify.com/s/files/1/0432/9019/8180/files/27429156034.pdf
- https://cdn.shopify.com/s/files/1/0486/5169/8344/files/bishop_rufus_kyles_2016.pdf
- https://cdn.shopify.com/s/files/1/0478/8348/5350/files/woodcutters_axe_botw.pdf
- https://uploads.strikinglycdn.com/files/1ede3a6c-84a7-4065-a3ad-5b4251c1a717/zosaxebanugadude.pdf
- https://uploads.strikinglycdn.com/files/74c9e73f-b45a-4d2e-873c-5ac742bf2b38/kerudusowarigalad.pdf
- https://uploads.strikinglycdn.com/files/fd86fac0-38ae-439b-82ba-c4e31117c54c/44730610888.pdf
- https://uploads.strikinglycdn.com/files/8e147ef7-d8d5-4c34-b643-2b1a6da70c05/21323735327.pdf
- https://uploads.strikinglycdn.com/files/75358e52-a52d-4b57-adf2-a263e480e488/javapukotufigobole.pdf
- http://files.santafeb2c.org/uploads/1/3/1/4/131406785/7476014.pdf
- http://files.dunlapcoc.org/uploads/1/3/0/7/130739945/6798277.pdf
- http://files.jimgatesrhc.com/uploads/1/3/1/4/131455463/8083292.pdf
- http://jidiratut.openmindspromotions.com/uploads/1/3/0/7/130740596/1801337.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- files.santafeb2c.org
- files.dunlapcoc.org
- files.jimgatesrhc.com
- jidiratut.openmindspromotions.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report