SUSPICIOUS — gugefa-refosofemekor.pdf
SUSPICIOUS — gugefa-refosofemekor.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
fb3f4b17a3d7fa6b5c87416241ed863c253113789f25ce53e487b13e4ee8072a - SHA-1:
b6175bef269c30c1de81f6bfbb00e7b7f1b33389 - MD5:
65c67c2072fd463e85c641ed594e25d7 - ssdeep:
768:ngGzpD2S/IEiPs0gzWWO8QqRIg2XOsVMioG9+WAuUB/TSUJ5Rj:gGFaMcgzWW/QDXxVMi/nUB/T9J5Rj - TLSH:
T16032ACF75097DE48ABCAAF037EFA118D544AD34D6122E63048D8772CC5BCAACBE44910 - Submitted as: gugefa-refosofemekor.pdf
- File type: pdf · Size: 46747 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafftec.ru/wb?keyword=club%20penguin%20guide, https://uploads.strikinglycdn.com/files/f151ae2f-ebff-496e-a865-851b6f761ca3/auto_repairs_for_dummies.pdf, https://uploads.strikinglycdn.com/files/2167c43c-f028-4b67-8263-2e1cd10044ca/where_are_the_customers_yachts_ebook.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/wb?keyword=club%20penguin%20guide
- https://s3.amazonaws.com/bulolimepol/campbell_biology_in_focus_third_edition.pdf
- https://uploads.strikinglycdn.com/files/f151ae2f-ebff-496e-a865-851b6f761ca3/auto_repairs_for_dummies.pdf
- https://s3.amazonaws.com/davolazupivowi/vojojobajimijisewipebet.pdf
- https://s3.amazonaws.com/gifiz/zebupanovukodopijukewevi.pdf
- https://uploads.strikinglycdn.com/files/2167c43c-f028-4b67-8263-2e1cd10044ca/where_are_the_customers_yachts_ebook.pdf
- https://s3.amazonaws.com/davubewu/37955955965.pdf
- https://uploads.strikinglycdn.com/files/61c4c6a3-b3a4-4063-9660-4cc2bb37b1d2/82998560724.pdf
- https://s3.amazonaws.com/subud/al_quran_word_by_word_translation.pdf
- https://s3.amazonaws.com/wonoti/96754356263.pdf
- https://s3.amazonaws.com/loxopudizus/66670845475.pdf
- https://uploads.strikinglycdn.com/files/40f7381c-ae6e-4b5c-bac1-7fd322ed7efe/scream_and_shout_clean_version_lyrics.pdf
- https://uploads.strikinglycdn.com/files/f1d38f17-7b84-4628-90d0-f7ba79d0fe88/73056405204.pdf
- https://rodamopuxex.weebly.com/uploads/1/3/4/3/134354351/gitumavawupe-zujunuxas-naludux.pdf
- https://s3.amazonaws.com/tuxenipup/dfghjkldghjdhdssghjkl_ertyuioopkl_7uio.pdf
- https://tibiwurab.weebly.com/uploads/1/3/2/6/132695994/vuzujilelapeper_revesixuna_pekorinasaw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafftec.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- rodamopuxex.weebly.com
- tibiwurab.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report