SUSPICIOUS — ferewi.pdf
SUSPICIOUS — ferewi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b6f68179c766cffef91210e632148bb9a70b655457aea1169e2fc5fe929c0001 - SHA-1:
045a09179844829860b6a6788cfd331b33c9ce6a - MD5:
0f36285196f793aa80b4aabe71c58922 - ssdeep:
768:EgGzpDZpSUhNhzP1AiNkrGAMQLcmNd05V+aO2nGq5MEJCV13:xGFVp6LcmP0NO2nGDV13 - TLSH:
T157339EF31097ED8C3A4B6F43AEAB1159608AD38D6135D7A044DC7B6CC57CAEEAE10610 - Submitted as: ferewi.pdf
- File type: pdf · Size: 47920 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=cardiovascular%20system%20worksheet%20middle%20school, https://cdn-cms.f-static.net/uploads/4393752/normal_5f8f3124b0915.pdf, https://cdn-cms.f-static.net/uploads/4382770/normal_5f8da7844611f.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=cardiovascular%20system%20worksheet%20middle%20school
- https://cdn-cms.f-static.net/uploads/4393752/normal_5f8f3124b0915.pdf
- https://cdn-cms.f-static.net/uploads/4382770/normal_5f8da7844611f.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f8b30eb9b0b8.pdf
- https://uploads.strikinglycdn.com/files/779fda26-9f31-4b5c-9a97-edc017430641/53178650930.pdf
- https://uploads.strikinglycdn.com/files/5a62c5c1-6fb9-4ac3-903a-7ce012652bcc/kejuvulitirexugisumawe.pdf
- https://uploads.strikinglycdn.com/files/050ee1e2-1b03-4074-ac57-736461d55a52/56479565784.pdf
- https://uploads.strikinglycdn.com/files/8c9eeba6-af8f-4bf0-91b1-f7e79fe18043/jimid.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/nidisetati.pdf
- https://moguvikob.weebly.com/uploads/1/3/0/8/130874292/7527046.pdf
- https://sizukejagu.weebly.com/uploads/1/3/2/6/132681884/pozorefuxileno.pdf
- https://wugemevafiditi.weebly.com/uploads/1/3/4/3/134382928/siboradenixepeg-wofafipomujuse-jebaf-jomewazanefiniv.pdf
- https://cdn.shopify.com/s/files/1/0495/8158/8632/files/diana_v_state_board_of_education_1970.pdf
- https://cdn.shopify.com/s/files/1/0428/3816/3623/files/lexigowuparururozujobawo.pdf
- https://cdn.shopify.com/s/files/1/0430/7877/9047/files/mixovaduwe.pdf
- https://cdn.shopify.com/s/files/1/0480/9441/2963/files/5118062264.pdf
- https://cdn.shopify.com/s/files/1/0430/6567/1833/files/amc_theater_showplace_edwardsville_illinois.pdf
- https://uploads.strikinglycdn.com/files/d6ccee1a-d0cf-4434-8aa1-519e8053b10b/fangirl_rainbow_rowell_free_download.pdf
- https://uploads.strikinglycdn.com/files/4f3e52ae-8f2e-42e4-a711-9f4cae0f3b37/15448213108.pdf
- https://uploads.strikinglycdn.com/files/4b977800-7c5f-4019-9fde-726bc59418fe/futhark_a_handbook_of_rune_magic.pdf
- https://uploads.strikinglycdn.com/files/b78a881f-514f-4683-a082-562b7458ca6c/jilamilikufeninarem.pdf
- https://uploads.strikinglycdn.com/files/541caf6a-c33d-425d-b56e-9fdfe925fe32/historia_del_magnetismo.pdf
- https://uploads.strikinglycdn.com/files/e031d21b-6bb7-4b58-9fb6-69dd5b2f3da7/safety_first_forehead_thermometer.pdf
- https://uploads.strikinglycdn.com/files/0a0ebc5c-4b6e-4192-ad6a-1d73fb7f88e5/matewo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- dutitujazekap.weebly.com
- moguvikob.weebly.com
- sizukejagu.weebly.com
- wugemevafiditi.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report