SUSPICIOUS — fasaga.pdf
SUSPICIOUS — fasaga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b3a10b107cc330f5179a64a647e8eef3274ee1a6be7fd56369fd4db832f4cc0f - SHA-1:
4fbbd770cb4c93d1324859c2a97532ed7e4e650a - MD5:
b2d78c09df0cbfbf8fe0bf22c166b670 - ssdeep:
768:agGzpDxp9x88UbLwXUvL9xs59fzzlrczusIO0g/cC18SLJ3aaKeZf1m:HGFtpL81wGsXzzmzuJWcC18YFaaPZtm - TLSH:
T1E3339DFB609BEC4C7A8A9B039DBB051A528AD38C6137DB10488C772CC57C6BD7E14861 - Submitted as: fasaga.pdf
- File type: pdf · Size: 49040 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4f6331a6-b571-43b7-8886-432501ddbe75/fujebumajizanetepakozemus.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=hands%20on%20machine%20learning%20with%20scikit-learn%20and%20tensorflow%202.0, https://uploads.strikinglycdn.com/files/4f6331a6-b571-43b7-8886-432501ddbe75/fujebumajizanetepakozemus.pdf, https://uploads.strikinglycdn.com/files/06b54032-ddc0-46c7-8348-797760dfc489/65016498882.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=hands%20on%20machine%20learning%20with%20scikit-learn%20and%20tensorflow%202.0
- https://uploads.strikinglycdn.com/files/4f6331a6-b571-43b7-8886-432501ddbe75/fujebumajizanetepakozemus.pdf
- https://uploads.strikinglycdn.com/files/06b54032-ddc0-46c7-8348-797760dfc489/65016498882.pdf
- https://uploads.strikinglycdn.com/files/05d2d9f1-5c00-4f78-8932-c7b47d3d8d5a/16842140723.pdf
- https://uploads.strikinglycdn.com/files/ba9dfa4d-625b-43de-99c7-967a7f1296e1/92359222954.pdf
- https://uploads.strikinglycdn.com/files/c05c55f7-8075-4dbd-9b5d-0409c00fd7e0/45521716733.pdf
- https://uploads.strikinglycdn.com/files/b6538220-cc90-4464-8f47-89af6fb09de0/vogowufum.pdf
- https://uploads.strikinglycdn.com/files/0ec8545e-e12c-413b-beca-40486076e620/autoformation_securit_informatique.pdf
- https://uploads.strikinglycdn.com/files/028933e9-1dce-42c8-9f5b-eeb6bd4e3e88/1940214532.pdf
- https://uploads.strikinglycdn.com/files/fed105e5-8307-4bbc-85c3-1015a3059315/setarojijageduw.pdf
- https://uploads.strikinglycdn.com/files/a75c0da6-ae9c-4ae2-a9a1-5f50a382b91d/munajubog.pdf
- https://cdn.shopify.com/s/files/1/0268/8427/6415/files/lekofemex.pdf
- https://cdn.shopify.com/s/files/1/0492/8929/8076/files/96912110803.pdf
- https://cdn.shopify.com/s/files/1/0433/5747/0872/files/probability_class_12.pdf
- https://fupexorugukemig.weebly.com/uploads/1/3/0/8/130814763/zifabovalos_zolapepi.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/a7b88.pdf
- https://babinekisifuve.weebly.com/uploads/1/3/2/6/132696104/sobofopamifefok_rasik_lefivegifab.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/059d55fbff3.pdf
- https://rolosakuzorega.weebly.com/uploads/1/3/1/3/131379035/kodegelo.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/6443274.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/kanasazizofowire.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/zipidaxif.pdf
- https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/rimexajugonarure.pdf
- https://cdn-cms.f-static.net/uploads/4384167/normal_5f8ee58e87e5f.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f8bf58e1a3d9.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- fupexorugukemig.weebly.com
- gevafitasib.weebly.com
- babinekisifuve.weebly.com
- mogilifus.weebly.com
- rolosakuzorega.weebly.com
- sesuwulot.weebly.com
- dutitujazekap.weebly.com
- zesopupejilit.weebly.com
- wosezobar.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report