SUSPICIOUS — fugabilatinaz.pdf
SUSPICIOUS — fugabilatinaz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
de7a987537e98c0dd0b3bca59eeb9f4808f80b27d58b9e1be2751d13428e041a - SHA-1:
277505b1a9dd1da626fe9a49a4acadc408e1e5f0 - MD5:
53f097e9f694c37f54c4e83691b51867 - ssdeep:
768:tgGzpDHpTUVhQMZe+kpn1+rNw+s8aphilkMT+KxjlF++AqSA1W8VM26BClbn:OGFDpNIlszp+T+KxjlRA4vwClbn - TLSH:
T18F328DF31097DD4D7E879B836CB71A65218983C96126A7A008CC776CD4BCABE7F105A0 - Submitted as: fugabilatinaz.pdf
- File type: pdf · Size: 46183 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=paises%20e%20nacionalidades%20em%20ingles%20exercicios, https://uploads.strikinglycdn.com/files/4e04856b-3edf-40d8-b9bb-02a7be5773cc/sogajadewarowan.pdf, https://uploads.strikinglycdn.com/files/347c0ed2-93b7-4318-970f-6d4310e5e294/rigeleba.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=paises%20e%20nacionalidades%20em%20ingles%20exercicios
- https://s3.amazonaws.com/zirojopemup/54552191445.pdf
- https://s3.amazonaws.com/tejuvonixag/aha_bls_ebook.pdf
- https://s3.amazonaws.com/pazifetanegapu/88420341758.pdf
- https://uploads.strikinglycdn.com/files/4e04856b-3edf-40d8-b9bb-02a7be5773cc/sogajadewarowan.pdf
- https://uploads.strikinglycdn.com/files/347c0ed2-93b7-4318-970f-6d4310e5e294/rigeleba.pdf
- https://uploads.strikinglycdn.com/files/1b5f9def-26cd-433a-8559-f6a9b3bfd00c/rigawurawu.pdf
- https://uploads.strikinglycdn.com/files/a63dcd98-524a-4932-8e8d-1d62b85fe4e6/zilurumamuwijo.pdf
- https://uploads.strikinglycdn.com/files/d7bd2c03-c50b-4326-9474-1289995c7363/9322191778.pdf
- https://uploads.strikinglycdn.com/files/cc1d7c0d-c9c2-41c4-9cf6-200daac83de4/43218249257.pdf
- https://cdn-cms.f-static.net/uploads/4368266/normal_5f909d46bf839.pdf
- https://cdn-cms.f-static.net/uploads/4391327/normal_5f8f87e0e097f.pdf
- https://cdn-cms.f-static.net/uploads/4366382/normal_5f8718039e4c6.pdf
- https://cdn-cms.f-static.net/uploads/4367271/normal_5f8738b0e94b1.pdf
- https://cdn-cms.f-static.net/uploads/4367000/normal_5f87d02de33f1.pdf
- https://cdn.shopify.com/s/files/1/0508/3660/3045/files/tecnicas_de_reproduccion_animal.pdf
- https://cdn.shopify.com/s/files/1/0431/8950/2110/files/27274966458.pdf
- https://cdn.shopify.com/s/files/1/0437/6713/6407/files/34716833995.pdf
- https://cdn.shopify.com/s/files/1/0501/8835/3715/files/dark_sky_weather_for_android_apk.pdf
- https://uploads.strikinglycdn.com/files/306c984b-7805-4f12-bd51-492122766a79/62740053271.pdf
- https://uploads.strikinglycdn.com/files/37e41701-0fbd-4807-8e4f-a9794b85b0e7/taguku.pdf
- https://uploads.strikinglycdn.com/files/1c1dad63-8362-40e0-acb7-bed3f1ea39a2/xinutu.pdf
- https://uploads.strikinglycdn.com/files/4b1da706-326c-40ff-9548-efe8a29f9b5e/zoruvaxarumejizuwugar.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report