SUSPICIOUS — fatulevusotuvadelug.pdf
SUSPICIOUS — fatulevusotuvadelug.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ee4237a578415abc37421945c3c96563bfd0f2ef5ab9118f3bbbc04dbe3be0ec - SHA-1:
b0c738818d0d7e951c83325969ba65175dcea93c - MD5:
a2feb787046b98b592a36f1cd6e04ee7 - ssdeep:
1536:1GFJefcVQro3vCpdsLq0G44NpvESG766yy6FxIbtHX7:IFJ0MQAqp6G0GZpvEN+jy6sr - TLSH:
T10734BFF360A3FDCC7B8B7F436D9740AA2185C2892522D7D106A93A6DC6782BC7F10561 - Submitted as: fatulevusotuvadelug.pdf
- File type: pdf · Size: 53624 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=computer+security+principles+and+practice+3rd+edition+solutions+manual+pdf, https://site-1036980.mozfiles.com/files/1036980/53286134702.pdf, https://site-1036850.mozfiles.com/files/1036850/2504734307.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=computer+security+principles+and+practice+3rd+edition+solutions+manual+pdf
- https://site-1036980.mozfiles.com/files/1036980/53286134702.pdf
- https://site-1036850.mozfiles.com/files/1036850/2504734307.pdf
- https://site-1036733.mozfiles.com/files/1036733/53413042779.pdf
- https://site-1040373.mozfiles.com/files/1040373/xujufibanuj.pdf
- https://site-1037009.mozfiles.com/files/1037009/10438619847.pdf
- https://cdn.shopify.com/s/files/1/0431/1118/6585/files/dofipapezakadatubategiv.pdf
- https://cdn.shopify.com/s/files/1/0481/7983/9143/files/functions_review_worksheet.pdf
- https://site-1037054.mozfiles.com/files/1037054/94589391541.pdf
- https://site-1036675.mozfiles.com/files/1036675/18390379333.pdf
- https://site-1038573.mozfiles.com/files/1038573/fokovosudibopegazuxup.pdf
- https://site-1036724.mozfiles.com/files/1036724/50469686520.pdf
- https://site-1039391.mozfiles.com/files/1039391/7523624776.pdf
- https://cdn.shopify.com/s/files/1/0481/6771/4983/files/wida_practice_test.pdf
- https://cdn.shopify.com/s/files/1/0483/2313/3604/files/mount_and_blade_warband_manual_activation_code_free.pdf
- https://cdn.shopify.com/s/files/1/0441/0372/9304/files/38124191152.pdf
- https://cdn.shopify.com/s/files/1/0432/3963/7155/files/aplia_accounting_chapter_5_study_guide_answers.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1036980.mozfiles.com
- site-1036850.mozfiles.com
- site-1036733.mozfiles.com
- site-1040373.mozfiles.com
- site-1037009.mozfiles.com
- cdn.shopify.com
- site-1037054.mozfiles.com
- site-1036675.mozfiles.com
- site-1038573.mozfiles.com
- site-1036724.mozfiles.com
- site-1039391.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report