SUSPICIOUS — fufumul.pdf
SUSPICIOUS — fufumul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
f9563abb6a0b7e075755f1dc0aa786773529ba62c665aac3eef75007164a34a9 - SHA-1:
d9c76fcc00dcaab60191ada666571fb495c136c5 - MD5:
c611cb7064231d87fd5a4068e8fe40e1 - ssdeep:
768:qgGzpDAeY6SDXL1740DtCJL+VvSXlil3fY008555cwEwlm7MgYo:3GF8es8hkfY00855lE6AMgYo - TLSH:
T178336CF300A7ED8CBA8B9B97ACAB0199608AC3497277975054C8B76DC0BC57DBF11520 - Submitted as: fufumul.pdf
- File type: pdf · Size: 48032 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=problemas%20de%20parabola%20resueltos, https://uploads.strikinglycdn.com/files/918884e4-28fa-463c-9bdb-cb35d636a101/20522967933.pdf, https://uploads.strikinglycdn.com/files/aab560db-bfe0-4e21-b3a2-d42c239a5006/vegutopasuwopemomi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=problemas%20de%20parabola%20resueltos
- https://uploads.strikinglycdn.com/files/918884e4-28fa-463c-9bdb-cb35d636a101/20522967933.pdf
- https://uploads.strikinglycdn.com/files/aab560db-bfe0-4e21-b3a2-d42c239a5006/vegutopasuwopemomi.pdf
- https://uploads.strikinglycdn.com/files/0dce732c-f5a1-4f06-96e5-a810881d9b5c/78512738219.pdf
- https://uploads.strikinglycdn.com/files/afd3aae6-8fcf-42be-acac-e95febcc6d7d/11913068942.pdf
- https://site-1042011.mozfiles.com/files/1042011/fesozafubisedem.pdf
- https://site-1037224.mozfiles.com/files/1037224/73867555724.pdf
- https://site-1039737.mozfiles.com/files/1039737/11908912683.pdf
- https://site-1037266.mozfiles.com/files/1037266/chess_titans_mod_apk.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f8701cc81aea.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f8740922b062.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f874fed542f0.pdf
- https://cdn-cms.f-static.net/uploads/4369336/normal_5f87b15424c39.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f870d993b6d5.pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/pazebazew.pdf
- https://wojeribexojuxu.weebly.com/uploads/1/3/1/8/131856158/futagofibavurexiwoli.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/2647249.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/1429013.pdf
- https://site-1036939.mozfiles.com/files/1036939/74023872747.pdf
- https://site-1036735.mozfiles.com/files/1036735/44537836622.pdf
- https://site-1036945.mozfiles.com/files/1036945/57702289473.pdf
- https://site-1037196.mozfiles.com/files/1037196/77174816362.pdf
- https://site-1043576.mozfiles.com/files/1043576/lusosanazi.pdf
- https://site-1048206.mozfiles.com/files/1048206/41886975224.pdf
- https://site-1039438.mozfiles.com/files/1039438/27302405057.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1042011.mozfiles.com
- site-1037224.mozfiles.com
- site-1039737.mozfiles.com
- site-1037266.mozfiles.com
- cdn-cms.f-static.net
- vekejuritikoj.weebly.com
- wojeribexojuxu.weebly.com
- vozunutav.weebly.com
- gevafitasib.weebly.com
- site-1036939.mozfiles.com
- site-1036735.mozfiles.com
- site-1036945.mozfiles.com
- site-1037196.mozfiles.com
- site-1043576.mozfiles.com
- site-1048206.mozfiles.com
- site-1039438.mozfiles.com
- site-1041950.mozfiles.com
- site-1038940.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report