SUSPICIOUS — fc82bc4da910a.pdf
SUSPICIOUS — fc82bc4da910a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e538f3f81b2e2f8f2c3ed1089e33cbfa537a71833a2b5622515edeffe6901945 - SHA-1:
9fde94b45020b5ff099db9e374b0a337a2808cbd - MD5:
11a1b34ce6ea4923b6f404ca41c37fda - ssdeep:
768:lgGzpDZmnJT4FZXtjI03NNGcga7sXtiij7LGAcrR8hmn:2GFl44XtjIKNNGSsXtieKAcrOhmn - TLSH:
T13F32AFF3409BDC8C3A87EF136ABB2099918ACB8D713396604458777DC47C2BD6E11962 - Submitted as: fc82bc4da910a.pdf
- File type: pdf · Size: 44573 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffnew.ru/wb?keyword=why%20i%20want%20a%20wife%20summary, https://uploads.strikinglycdn.com/files/43c0756b-c31b-486d-85cc-5f86c49c4c72/gunogipixajatoginixowabu.pdf, https://tijabitosivu.weebly.com/uploads/1/3/4/3/134396728/3386753.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffnew.ru/wb?keyword=why%20i%20want%20a%20wife%20summary
- https://vivuvegutofo.files.wordpress.com/2020/11/bpp_acca_f3_revision_kit.pdf
- https://uploads.strikinglycdn.com/files/43c0756b-c31b-486d-85cc-5f86c49c4c72/gunogipixajatoginixowabu.pdf
- https://tijabitosivu.weebly.com/uploads/1/3/4/3/134396728/3386753.pdf
- https://tugoxalimirufa.weebly.com/uploads/1/3/4/3/134310877/d8b180ee.pdf
- https://uploads.strikinglycdn.com/files/9cc0aafa-563d-4ab8-8e6a-ff1b1ffac6b8/74226317632.pdf
- https://s3.amazonaws.com/dogazisuze/13588849247.pdf
- https://dajedenutiwifux.weebly.com/uploads/1/3/4/3/134318988/volomotizur.pdf
- https://konomalipu.files.wordpress.com/2020/11/windows_95_img_file_for_limbo_download.pdf
- https://wotenopofe.files.wordpress.com/2020/11/budixaw.pdf
- https://modiginofom.files.wordpress.com/2020/11/46949602789.pdf
- https://s3.amazonaws.com/gumagabu/35195164224.pdf
- https://nejefala.files.wordpress.com/2020/11/freddy_fazbears_fright.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffnew.ru
- vivuvegutofo.files.wordpress.com
- uploads.strikinglycdn.com
- tijabitosivu.weebly.com
- tugoxalimirufa.weebly.com
- s3.amazonaws.com
- dajedenutiwifux.weebly.com
- konomalipu.files.wordpress.com
- wotenopofe.files.wordpress.com
- modiginofom.files.wordpress.com
- nejefala.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report