SUSPICIOUS — fiweserofevofotejivedaf.pdf
SUSPICIOUS — fiweserofevofotejivedaf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d28a8b8aca2e89b2b5df581773716bd6784f7d1380dfbb48dc9649727dab3dac - SHA-1:
2d0b1c7c6176db1d9f1d38bb76bd91dbf6fe821a - MD5:
f746a1434577b1a8fa615fe4d2a6ab5a - ssdeep:
768:KgGzpDLnhfy7QslPDLlPtQawchdjJbMzrT/Ru:XGFvnuCaez/5u - TLSH:
T10D31AEF34097DE8C7A866B036DE605A8104AD78DA13397B058D97B7DC0BC6BD7E109A0 - Submitted as: fiweserofevofotejivedaf.pdf
- File type: pdf · Size: 41062 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=ansoff+matrix+template+pdf, https://site-1037203.mozfiles.com/files/1037203/lebomowovolo.pdf, https://site-1036689.mozfiles.com/files/1036689/wezijafe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=ansoff+matrix+template+pdf
- https://site-1037203.mozfiles.com/files/1037203/lebomowovolo.pdf
- https://site-1036689.mozfiles.com/files/1036689/wezijafe.pdf
- https://site-1036996.mozfiles.com/files/1036996/ritijetobizasonep.pdf
- https://site-1036920.mozfiles.com/files/1036920/duvoluwaxoze.pdf
- https://site-1036811.mozfiles.com/files/1036811/8593818979.pdf
- https://uploads.strikinglycdn.com/files/0c5eddd8-2e2a-4280-99c1-e4ab2ecb4bfe/jefoxiwusifanu.pdf
- https://uploads.strikinglycdn.com/files/62013ec3-2b3e-4988-9a68-d46896def086/dowuvuxug.pdf
- https://uploads.strikinglycdn.com/files/e5487b7d-6f5d-4309-8405-e6277f0cf991/26323968709.pdf
- https://uploads.strikinglycdn.com/files/9921205e-5196-48db-828f-9cbb394e13ed/99647052398.pdf
- https://uploads.strikinglycdn.com/files/c48604ec-4b95-49ee-a0ef-72acce6e1867/zejifakazirofiputemema.pdf
- http://files.cincigreyhounds.com/uploads/1/3/1/3/131383924/biderujulalifotasume.pdf
- http://files.adamcarter.plumbing/uploads/1/3/2/3/132303138/sadabip.pdf
- http://files.csnons.org/uploads/1/3/1/4/131438829/poxamusavaxowajuk.pdf
- https://site-1038782.mozfiles.com/files/1038782/5947833089.pdf
- https://site-1036818.mozfiles.com/files/1036818/74123698812.pdf
- https://site-1037860.mozfiles.com/files/1037860/26559650530.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1037203.mozfiles.com
- site-1036689.mozfiles.com
- site-1036996.mozfiles.com
- site-1036920.mozfiles.com
- site-1036811.mozfiles.com
- uploads.strikinglycdn.com
- files.cincigreyhounds.com
- files.csnons.org
- site-1038782.mozfiles.com
- site-1036818.mozfiles.com
- site-1037860.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.adamcarter.plumbing
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report