MALICIOUS — fefubulaguwobezitasi.pdf
MALICIOUS — fefubulaguwobezitasi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
ce20aff8f462270dea9493aa99f65b72868adccbb771407387c3c7f74df1c078 - SHA-1:
5f7bbfdc63e5749c14f34b9a60bcf9f4ecd6186a - MD5:
f92aa89e981988be86ddb859aa81a0ea - ssdeep:
1536:RGFuponBXMm08jYU2TYs5Qok9OUMs82pEhC8GXgc:0Fuponj0ybok9OUPLF8E - TLSH:
T1E534AEF7548BDD5C3E9BAB13ADAB2598118EC78C2126D7504888376CC4BC6BDBE50860 - Submitted as: fefubulaguwobezitasi.pdf
- File type: pdf · Size: 57076 bytes
- Verdict: malicious (70/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://ggtraff.ru/wb?keyword=psychology%20an%20exploration%203rd%20edition%20pdf%20free%20download, https://wejibuxod.weebly.com/uploads/1/3/0/7/130740202/repaxolugebup_mabilebopivusad_purekesuvuj.pdf, https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/1d1f8ecc085ca.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=psychology%20an%20exploration%203rd%20edition%20pdf%20free%20download
- https://wejibuxod.weebly.com/uploads/1/3/0/7/130740202/repaxolugebup_mabilebopivusad_purekesuvuj.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/1d1f8ecc085ca.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/d1db2.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/kufaluduvubit.pdf
- https://uploads.strikinglycdn.com/files/6a226e50-d118-415d-bfda-2db1a662a201/87360030464.pdf
- https://uploads.strikinglycdn.com/files/796b273c-58dc-469f-bd79-257f7ba2dea3/lobetotod.pdf
- https://uploads.strikinglycdn.com/files/afdafa2f-0a7b-452e-a4f2-4f2866d220ab/85962539461.pdf
- https://uploads.strikinglycdn.com/files/8ebbd6c5-e84c-4422-a6a8-44a779f634ca/21599199647.pdf
- https://cdn-cms.f-static.net/uploads/4376374/normal_5f8aea1900245.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f89eff90d9b3.pdf
- https://cdn-cms.f-static.net/uploads/4383688/normal_5f8f615c9d52d.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f8d566d6d027.pdf
- https://uploads.strikinglycdn.com/files/7519e2b3-7e2c-48ca-9539-8e7ef9eb2fa7/76377830061.pdf
- https://uploads.strikinglycdn.com/files/2db5985d-103e-4b88-8b03-dc835aaaa281/diwezetomivoxozupetik.pdf
- https://uploads.strikinglycdn.com/files/b50f3071-54e3-48f4-b8ce-1288731b9a78/jeweseburoxafotanixet.pdf
- https://s3.amazonaws.com/henghuili-files2/92981194960.pdf
- https://s3.amazonaws.com/kavitokolezub/52524640000.pdf
- https://s3.amazonaws.com/xanebavifamopez/audit_report_of_tata_motors.pdf
- https://uploads.strikinglycdn.com/files/4eaf2fc9-3fde-4010-bab4-9eea4103d425/81760110705.pdf
- https://uploads.strikinglycdn.com/files/747e6370-ac97-4cd1-b61c-dcaf7190151b/56332643925.pdf
- https://uploads.strikinglycdn.com/files/55a46115-6844-4fd2-94e1-b11c5115d1e4/battletech_backer_beta.pdf
- https://uploads.strikinglycdn.com/files/a48c3d64-775b-4dbc-a633-f698cc54365f/26641067654.pdf
- https://uploads.strikinglycdn.com/files/14121d91-2674-4454-bf1e-b40e287aa096/5676474456.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- wejibuxod.weebly.com
- mogilifus.weebly.com
- pumowurunumig.weebly.com
- genigudepa.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report